Match Sequence
Sample Access List
Cuda 12000 IP Access Switch CLI-based Administration Guide
With the added permit any rule, only packets from the 172.16.19.20 are
rejected, all others pass. This is because once the permit any condition is
met, no further lines in the access list are read.
The sequence in which an inbound or outbound packet is matched against
the filter criteria of an interface is determined by the following:
Rule number within access list — Lower rule numbers take
precedence over higher rule numbers. This means that within an access
list, the rule with the lower number is examined first.
Priority of access-list within the access class — When you apply an
access-list to an interface, access lists assigned lower priorities take
precedence over lists assigned higher priorities. This means that within an
access class, the access list with the lower number is examined first.
The following example configures cable interface 1/1/1 to permit all IP traffic
except Telnet (TCP 23):
Packet Filtering Considerations and Example
341