ACCESS-LIST 12 - 5
Parameters
deny ip [<source-IP>|any|host
<IP>][<dest-IP>|any|host <IP>]
{log} {rule-precedence
<1-5000>}
Use with the deny command to reject packets
• deny – Sets the action type on an ACL
• IP – Specifies an IP address
• <source-ip>|any|host <IP> – The keyword <source-IP> is the source IP
address of the network or host in dotted decimal format.
• any – any is an abbreviation for a source IP of 0.0.0.0 and
source-mask bits equal to 0
• host – host is an abbreviation for the exact source <ip> (A.B.C.D
format) and source-mask bits equal to 32
• <dest-IP>|any|host <IP> – Defines the destination host IP address or
destination network address
• log – Generates log messages when the packet coming from the
interface matches an ACL entry. Log messages are generated only for
router ACLs
• rule-precedence <1-5000> – Defines an integer value between
1-5000. This value sets the rule precedence in the ACL
deny icmp [<source-
IP>|any|host <IP>]
[<dest-IP>|any|host <IP>]
{<ICMP-type>
{<ICMP-code>}} {log}
{rule-precedence <1-5000>}
Use with the deny command to reject ICMP packets
• deny – Rejects ICMP packets
• icmp – Specifies ICMP as the protocol
• <source-ip>|any|host <IP>] – The source <source-IP> is the source IP
address of the network or host (in dotted decimal format)
• any – any is an abbreviation for a source IP of 0.0.0.0 and
source-mask bits equal to 0
• host – host is an abbreviation for exact source (A.B.C.D) and source-
mask bits equal to 32
• <dest-IP>|any|host <IP>] – Defines the destination host IP address or
destination network address
• <ICMP-type> {<ICMP-code>} – Sets the ICMP type value
<ICMP-type> from 0 to 255, and is valid only for ICMP. The ICMP code
value <ICMP-code> is from 0 to 255, and is valid only for ICMP
• log – Generates log messages when a packet coming from an
interface matches an ACL entry. Log messages are generated only for
router ACLs
• rule-precedence <1-5000> – Optional. Defines an integer value
between 1-5000. This value sets the rule precedence in the ACL
Comments to this Manuals