IOS – edit access lists using line numbers
Tuesday, August 4th, 2009
Cisco 876 – C870-ADVSECURITYK9-M – 12.4
c876#conf t
c876(config)#service sequence-numbers
c876(config)#^Z
c876#sh run | i service
no service pad
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
c876(config)#ip access-list extended 111
c876(config-ext-nacl)#remark allow NMS
c876(config-ext-nacl)#10 permit ip 192.168.10.0 0.0.0.31 host 192.168.1.1
c876(config-ext-nacl)#20 permit ip 192.168.20.128 0.0.0.31 host 192.168.1.1
c876(config-ext-nacl)#remark allow tacacs
c876(config-ext-nacl)#30 permit ip 192.168.0.0 0.0.127.255 host 192.168.200.200
c876(config-ext-nacl)#40 permit ip 192.168.0.0 0.0.127.255 host 192.168.222.222
c876(config-ext-nacl)#50 deny ip any any log
c876(config-ext-nacl)#^Z
c876#sh ip access-lists 111
Extended IP access list 111
10 permit ip 192.168.10.0 0.0.0.31 host 192.168.1.1
20 permit ip 192.168.20.128 0.0.0.31 host 192.168.1.1
30 permit ip 192.168.0.0 0.0.127.255 host 192.168.200.200
40 permit ip 192.168.0.0 0.0.127.255 host 192.168.222.222
50 deny ip any any log
c876#conf t
c876(config)#ip access-list extended 111
c876(config-ext-nacl)#no 30
c876(config-ext-nacl)#^Z
c876#sh ip access-lists 111
Extended IP access list 111
10 permit ip 192.168.10.0 0.0.0.31 host 192.168.1.1
20 permit ip 192.168.20.128 0.0.0.31 host 192.168.1.1
40 permit ip 192.168.0.0 0.0.127.255 host 192.168.222.222
50 deny ip any any log
c876#conf t
c876(config)#ip access-list extended 111
c876(config-ext-nacl)#30 permit ip 172.20.10.0 0.0.0.0 host 192.168.222.222
c876(config-ext-nacl)#^Z
c876#sh ip access-lists 111
Extended IP access list 111
10 permit ip 192.168.10.0 0.0.0.31 host 192.168.1.1
20 permit ip 192.168.20.128 0.0.0.31 host 192.168.1.1
30 permit ip host 172.20.10.0 host 192.168.222.222
40 permit ip 192.168.0.0 0.0.127.255 host 192.168.222.222
50 deny ip any any log