Chapter 9. Security

Access Lists / Extended IP Access Lists

Many types of access lists are available in Cisco IOS Software for many different protocols. See Table 9-1 for a complete list.

Table 9-1 Cisco IOS Software Access Lists

image

You are permitted one access list per protocol, per interface, per direction.

Figure 9-1 Access Control Lists

image

At the end of every access list is an implied deny-all-traffic access control entry (ACE). Therefore, if a packet does not match any of your criteria statements, it is blocked.

Remember that the order of access ...

Get CCIE Routing and Switching v4.0 Quick Reference, Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.