Creating Standard And Extended Ip Acls; Acl Numbers - Cisco Catalyst 2950 Software Manual

Desktop switch software configuration guide
Hide thumbs Also See for Catalyst 2950:
Table of Contents

Advertisement

Chapter 12
Configuring Network Security with ACLs

Creating Standard and Extended IP ACLs

This section describes how to create switch IP ACLs. An ACL is a sequential collection of permit and
deny conditions. The switch tests packets against the conditions in an access list one by one. The first
match determines whether the switch accepts or rejects the packet. Because the switch stops testing
conditions after the first match, the order of the conditions is critical. If no conditions match, the switch
denies the packet.
Use these steps to use ACLs:
Step 1
Create an ACL by specifying an access list number or name and access conditions.
Step 2
Apply the ACL to interfaces or terminal lines.
The software supports these styles of ACLs or IP access lists:
The next sections describe access lists and the steps for using them.

ACL Numbers

The number you use to denote your ACL shows the type of access list that you are creating.
lists the access list number and corresponding type and shows whether or not they are supported by the
switch. The Catalyst 2950 switch supports IP standard and IP extended access lists, numbers 1 to 199
and 1300 to 2699.
Table 12-2 Access List Numbers
ACL Number
1–99
100–199
200–299
300–399
400–499
500–599
600–699
700–799
800–899
900–999
1000–1099
1100–1199
78-11380-03
Standard IP access lists use source addresses for matching operations.
Extended IP access lists use source and destination addresses for matching operations and optional
protocol-type information for finer granularity of control.
MAC extended access list use source and destination MAC addresses and optional protocol type
information for matching operations.
Type
IP standard access list
IP extended access list
Protocol type-code access list
DECnet access list
XNS standard access list
XNS extended access list
AppleTalk access list
48-bit MAC address access list
IPX standard access list
IPX extended access list
IPX SAP access list
Extended 48-bit MAC address access list
Supported
Yes
Yes
No
No
No
No
No
No
No
No
No
No
Catalyst 2950 Desktop Switch Software Configuration Guide
Configuring ACLs
Table 12-2
12-7

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents