1-1
1
ACL Overview
An access control list (ACL) is a set of rules (that is, a set of permit or deny statements) for identifying
traffic based on matching criteria such as source address, destination address, and port number. The
selected traffic will then be permitted or rejected by predefined security policies.
ACLs are widely used in technologies where traffic identification is desired, such as packet filtering and
QoS.
Unless otherwise stated, ACLs refer to both IPv4 ACLs and IPv6 ACLs throughout this document.
Go to these sections for information you are interested in:
z
Introduction to IPv4 ACL
z
Introduction to IPv6 ACL
z
ACL Application
Introduction to IPv4 ACL
This section covers these topics:
z
IPv4 ACL Classification
z
IPv4 ACL Naming
z
IPv4 ACL Match Order
z
IPv4 ACL Step
z
Effective Period of an IPv4 ACL
z
IP Fragments Filtering with IPv4 ACL
IPv4 ACL Classification
IPv4 ACLs, identified by ACL numbers, fall into three categories, as shown in
Table 1-1
.
Table 1-1
IPv4 ACL categories
Category
ACL number
Matching criteria
Basic IPv4 ACL
2000 to 2999
Source IP address