IOS – edit access lists using line numbers

Tuesday, August 4th, 2009


Cisco 876 – C870-ADVSECURITYK9-M – 12.4

c876#conf t
c876(config)#service sequence-numbers
c876(config)#^Z
c876#sh run | i service

no service pad
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers

c876(config)#ip access-list extended 111
c876(config-ext-nacl)#remark allow NMS
c876(config-ext-nacl)#10 permit ip 192.168.10.0 0.0.0.31 host 192.168.1.1
c876(config-ext-nacl)#20 permit ip 192.168.20.128 0.0.0.31 host 192.168.1.1
c876(config-ext-nacl)#remark allow tacacs
c876(config-ext-nacl)#30 permit ip 192.168.0.0 0.0.127.255 host 192.168.200.200
c876(config-ext-nacl)#40 permit ip 192.168.0.0 0.0.127.255 host 192.168.222.222
c876(config-ext-nacl)#50 deny ip any any log
c876(config-ext-nacl)#^Z

c876#sh ip access-lists 111

Extended IP access list 111
10 permit ip 192.168.10.0 0.0.0.31 host 192.168.1.1
20 permit ip 192.168.20.128 0.0.0.31 host 192.168.1.1
30 permit ip 192.168.0.0 0.0.127.255 host 192.168.200.200
40 permit ip 192.168.0.0 0.0.127.255 host 192.168.222.222
50 deny ip any any log

c876#conf t
c876(config)#ip access-list extended 111
c876(config-ext-nacl)#no 30
c876(config-ext-nacl)#^Z
c876#sh ip access-lists 111

Extended IP access list 111
10 permit ip 192.168.10.0 0.0.0.31 host 192.168.1.1
20 permit ip 192.168.20.128 0.0.0.31 host 192.168.1.1
40 permit ip 192.168.0.0 0.0.127.255 host 192.168.222.222
50 deny ip any any log

c876#conf t
c876(config)#ip access-list extended 111
c876(config-ext-nacl)#30 permit ip 172.20.10.0 0.0.0.0 host 192.168.222.222
c876(config-ext-nacl)#^Z
c876#sh ip access-lists 111

Extended IP access list 111
10 permit ip 192.168.10.0 0.0.0.31 host 192.168.1.1
20 permit ip 192.168.20.128 0.0.0.31 host 192.168.1.1
30 permit ip host 172.20.10.0 host 192.168.222.222
40 permit ip 192.168.0.0 0.0.127.255 host 192.168.222.222
50 deny ip any any log

Comments are closed.