注意:标准ACL删除将删除整个ACL。
扩展ACL 。
Cisco3750#sh access-lists
Standard IP access list 98
10 permit 192.168.20.10
20 permit 192.168.20.200
Extended IP access list VLAN30_ACL
10 deny ip 192.168.20.0 0.0.0.255 any
20 permit ip any any
Extended IP access list test
10 permit ip host 192.168.20.1 host 192.168.1.1
20 deny ip any any
有时候已经无法再插入的时候怎么办?
Cisco3750(config)#ip access-list ?
extended Extended Access List
log-update Control access list log updates
logging Control access list logging
resequence Resequence Access List
standard Standard Access List
Cisco3750(config)#ip access-list resequence test 20 30 ?
<cr>
20表示起始序号,30表示每次递加数。
调整后的效果。
Cisco3750#sh access-lists test
Extended IP access list test
20 permit ip host 192.168.20.1 host 192.168.1.1
50 deny ip any any