.1166..44..00 00..00..00..225555 aannyy eeqq 2233
RouterX(config-ext-nacl)#ppeerrmmiitt iipp aannyy aannyy
RouterX(config-ext-nacl)#iinntteerrffaaccee ee00
RouterX(config-if)#iipp aacccceessss--ggrroouupp bbaaddggrroouupp oouutt
Table 6-11 Named Extended IPv4 ACL Example Denying Telnet from a Subnet
access-list Command
Parameter Description
extended Indicates that the named ACL is an extended ACL.
badgroup Name of the ACL.
deny Indicates that traf?¬?c that matches the selected parameters is not
forwarded.
tcp Transport layer protocol.
172.16.4.0 0.0.0.255 Source IP address and mask; the ?¬?rst three octets must match but not
the last octet.
any Match any destination IP address.
eq 23 or eq telnet Destination port or application name. In this example, it speci?¬?es the
well-known port number for Telnet, which is 23.
permit Indicates that traf?¬?c that matches the selected parameters is
forwarded.
ip Network layer protocol.
any Keyword matching traf?¬?c to any source and destination.
ip access-group badgroup out Links ACL ???badgroup??? to interface E0 as an output ?¬?lter.
Troubleshooting ACLs 239
Each remark line is limited to 100 characters.
Pages:
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363