•
Whether per-entry statistics are configured for the ACL.
•
Whether the
fragments
command is configured for the ACL.
•
The number of rules in the ACL configuration. This number does not reflect how many entries that the
ACL contains when the device applies it to an interface. If a rule in the ACL uses an object group, the
number of entries in the ACL when it is applied may be much greater than the number of rules.
•
The interfaces that the ACL is applied to.
•
The interfaces that the ACL is active on.
The
show ip access-lists
command displays statistics for each entry in an ACL if the following conditions
are both true:
•
The ACL configuration contains the
statistics per-entry
command.
•
The ACL is applied to an interface that is administratively up.
If an IP ACL includes the
fragments
command, it appears before the explicit permit and deny rules, but the
device applies the
fragments
command to noninitial fragments only if they do not match all other explicit
rules in the ACL.
This command does not require a license.
Examples
This example shows how to use the
show ip access-lists
command to display all IPv4 ACLs on a device that
has a single IPv4 ACL:
switch#
show ip access-lists
IP access list ipv4-open-filter
10 permit ip any any
This example shows how to use the
show ip access-lists
command to display an IPv4 ACL named
ipv4-RandD-outbound-web, including per-entry statistics for the entries except for the MainLab object group:
switch#
show ip access-lists ipv4-RandD-outbound-web
IP access list ipv4-RandD-outbound-web
statistics per-entry
fragments deny-all
1000 permit ahp any any [match=732]
1005 permit tcp addrgroup MainLab any eq telnet
1010 permit tcp any any eq www [match=820421]
This example shows how to use the
show ip access-lists
command to display an IPv4 ACL named
ipv4-RandD-outbound-web. The
expanded
keyword causes the contents of the object group from the previous
example to appear, including the per-entry statistics:
switch#
show ip access-lists ipv4-RandD-outbound-web expanded
IP access list ipv4-RandD-outbound-web
statistics per-entry
1000 permit ahp any any [match=732]
1005 permit tcp 10.52.34.4/32 any eq telnet [match=5032]
1005 permit tcp 10.52.34.27/32 any eq telnet [match=433]
1010 permit tcp any any eq www [match=820421]
This example shows how to use the
show ip access-lists
command with the
summary
keyword to display
information about an IPv4 ACL named ipv4-RandD-outbound-web, such as which interfaces the ACL is
applied to and active on:
switch#
show ip access-lists ipv4-RandD-outbound-web summary
IPV4 ACL ipv4-RandD-outbound-web
Statistics enabled
Cisco Nexus 7000 Series Security Command Reference
779
Show Commands
show ip access-lists
Содержание Nexus 7000 Series
Страница 2: ... Cisco Systems Inc All rights reserved ...
Страница 20: ...Cisco Nexus 7000 Series Security Command Reference xx Contents ...
Страница 62: ...Cisco Nexus 7000 Series Security Command Reference 36 A Commands aaa authentication rejected ...
Страница 78: ...Cisco Nexus 7000 Series Security Command Reference 52 A Commands aaa user default role ...
Страница 157: ...Cisco Nexus 7000 Series Security Command Reference 131 C Commands crypto ca import ...
Страница 172: ...Cisco Nexus 7000 Series Security Command Reference 146 C Commands cts role based sgt map ...
Страница 186: ...Cisco Nexus 7000 Series Security Command Reference 160 C Commands cts role based access list ...
Страница 190: ...Cisco Nexus 7000 Series Security Command Reference 164 C Commands cts role based detailed logging ...
Страница 256: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 230 D Commands deny IPv4 ...
Страница 271: ...protocol Cisco Nexus 7000 Series Security Command Reference 245 D Commands deny IPv6 ...
Страница 274: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 248 D Commands deny IPv6 ...
Страница 291: ...Cisco Nexus 7000 Series Security Command Reference 265 D Commands description identity policy ...
Страница 293: ...Cisco Nexus 7000 Series Security Command Reference 267 D Commands description user role ...
Страница 299: ...Cisco Nexus 7000 Series Security Command Reference 273 D Commands device role ...
Страница 313: ...Cisco Nexus 7000 Series Security Command Reference 287 E Commands enable Cert DN match ...
Страница 340: ...Cisco Nexus 7000 Series Security Command Reference 314 E Commands eq ...
Страница 344: ...Cisco Nexus 7000 Series Security Command Reference 318 F Commands feature cts ...
Страница 350: ...Cisco Nexus 7000 Series Security Command Reference 324 F Commands feature ldap ...
Страница 369: ...G Commands gt page 344 Cisco Nexus 7000 Series Security Command Reference 343 ...
Страница 372: ...Cisco Nexus 7000 Series Security Command Reference 346 G Commands gt ...
Страница 398: ...Cisco Nexus 7000 Series Security Command Reference 372 I Commands interface policy deny ...
Страница 454: ...Cisco Nexus 7000 Series Security Command Reference 428 I Commands ip udp relay subnet broadcast ...
Страница 470: ...Cisco Nexus 7000 Series Security Command Reference 444 I Commands ipv6 dhcp ldra attach policy interface ...
Страница 497: ...Cisco Nexus 7000 Series Security Command Reference 471 K Commands key config key ...
Страница 504: ...Cisco Nexus 7000 Series Security Command Reference 478 K Commands key string ...
Страница 518: ...Cisco Nexus 7000 Series Security Command Reference 492 L Commands It ...
Страница 536: ...Cisco Nexus 7000 Series Security Command Reference 510 M Commands monitor session ...
Страница 537: ...N Commands nac enable page 512 neq page 513 Cisco Nexus 7000 Series Security Command Reference 511 ...
Страница 543: ...Cisco Nexus 7000 Series Security Command Reference 517 O Commands object group identity policy ...
Страница 552: ...Cisco Nexus 7000 Series Security Command Reference 526 O Commands other config flag ...
Страница 569: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 543 P Commands permit IPv4 ...
Страница 584: ...protocol Cisco Nexus 7000 Series Security Command Reference 558 P Commands permit IPv6 ...
Страница 587: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 561 P Commands permit IPv6 ...
Страница 622: ...Cisco Nexus 7000 Series Security Command Reference 596 P Commands propagate sgt ...
Страница 664: ...Cisco Nexus 7000 Series Security Command Reference 638 R Commands rule ...
Страница 714: ...Cisco Nexus 7000 Series Security Command Reference 688 S Commands switchport port security violation ...
Страница 737: ...Cisco Nexus 7000 Series Security Command Reference 711 Show Commands show arp access lists ...
Страница 841: ...Cisco Nexus 7000 Series Security Command Reference 815 Show Commands show ipv6 dhcp ldra ...
Страница 992: ...Cisco Nexus 7000 Series Security Command Reference 966 T Commands trustedCert ...
Страница 1015: ...Cisco Nexus 7000 Series Security Command Reference 989 V Commands vlan policy deny ...
Страница 1017: ...Cisco Nexus 7000 Series Security Command Reference 991 V Commands vrf policy deny ...
Страница 1018: ...Cisco Nexus 7000 Series Security Command Reference 992 V Commands vrf policy deny ...