Show access-list ip mask-precedence – Accton Technology ES5508 User Manual

Page 308

background image

Command Line Interface

4-96

4

This is a more comprehensive example. It denies any TCP packets in which the
SYN bit is ON, and permits all other packets. It then sets the ingress mask to check
the deny rule first, and finally binds port 1 to this ACL. Note that once the ACL is
bound to an interface (i.e., the ACL is active), the order in which the rules are
displayed is determined by the associated mask.

show access-list ip mask-precedence

This command shows the ingress or egress rule masks for IP ACLs.

Syntax

show access-list ip mask-precedence [in | out]

• in – Ingress mask precedence for ingress ACLs.
• out – Egress mask precedence for egress ACLs.

Command Mode

Privileged Exec

Example

Switch(config)#access-list ip extended 6
Switch(config-ext-acl)#permit any any
Switch(config-ext-acl)#deny tcp any any control-flag 2 2
Switch(config-ext-acl)#end
Console#show access-list
IP extended access-list A6:

permit any any
deny tcp any any control-flag 2 2

Console#configure
Switch(config)#access-list ip mask-precedence in
Switch(config-ip-mask-acl)#mask protocol any any control-flag 2
Switch(config-ip-mask-acl)#end
Console#sh access-list
IP extended access-list A6:

permit any any
deny tcp any any control-flag 2 2

IP ingress mask ACL:

mask protocol any any control-flag 2

Console#configure
Console(config)#interface ethernet 1/1
Console(config-if)#ip access-group A6 in
Console(config-if)#end
Console#show access-list
IP extended access-list A6:

deny tcp any any control-flag 2 2
permit any any

IP ingress mask ACL:

mask protocol any any control-flag 2

Console#

Console#show access-list ip mask-precedence
IP ingress mask ACL:

mask host any
mask 255.255.255.0 any

Console#