permit tcp source source-wildcard destination destination-wildcard range 15 160
permit tcp source source-wildcard destination destination-wildcard range 115 1660
or
•
Rename the ACL with a name or number that alphanumerically precedes the other ACLs (for example,
rename ACL
79
to ACL
1
).
You can now apply the first ACE in the ACL to the interface. The switch allocates the ACE to available
mapping bits in the Opselect index and then allocates flag-related operators to use the same bits in the hardware
memory.
IPv4 ACL Configuration Examples
This section provides examples of configuring and applying IPv4 ACLs. For detailed information about
compiling ACLs, see the
Cisco IOS Security Configuration Guide, Release 12.4
and to the Configuring IP
Services
”
section in the
“
IP Addressing and Services
”
chapter of the
Cisco IOS IP Configuration Guide, Release
12.4.
ACLs in a Small Networked Office
This shows a small networked office environment with routed Port 2 connected to Server A, containing benefits
and other information that all employees can access, and routed Port 1 connected to Server B, containing
confidential payroll data. All users can access Server A, but Server B has restricted access.
Figure 6: Using Router ACLs to Control Traffic
Use router ACLs to do this in one of two ways:
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
182
OL-29048-01
Configuring IPv4 ACLs
IPv4 ACL Configuration Examples