Use IP access control entries (ACEs) to filter on the source IP address, destination IP address, DiffServ Code Point (DSCP), protocol, IP options, IP fragmentation parameters, and routed packets.
default filter acl ace ip <1-2048> <1-2000>
filter acl ace ip <1-2048> <1-2000> dscp eq <0-63 | 0-63>
filter acl ace ip <1-2048> <1-2000> dst-ip eq {A.B.C.D}
filter acl ace ip <1-2048> <1-2000> dst-ip mask {A.B.C.D} <0-32>
filter acl ace ip <1-2048> <1-2000> dst-ip mask {A.B.C.D} {A.B.C.D}
filter acl ace ip <1-2048> <1-2000> dst-ip range {A.B.C.D} {A.B.C.D}
filter acl ace ip <1-2048> <1-2000> ip-frag-flag eq { noFragment | anyFragment }
filter acl ace ip <1-2048> <1-2000> ip-options any
filter acl ace ip <1-2048> <1-2000> ip-protocol-type eq WORD<1-256>
filter acl ace ip <1-2048> <1-2000> src-ip eq {A.B.C.D}
filter acl ace ip <1-2048> <1-2000> src-ip mask {A.B.C.D} <0-32>
filter acl ace ip <1-2048> <1-2000> src-ip mask {A.B.C.D} {A.B.C.D}
filter acl ace ip <1-2048> <1-2000> dscp mask <0-63 | 0-63> <0-0x40 | 0x0-0x0>
filter acl ace ip <1-2048> <1-2000> dst-ip eq WORD <1-1024>
filter acl ace ip <1-2048> <1-2000> routed-only
no filter acl ace ip <1-2048> <1-2000> dscp
no filter acl ace ip <1-2048> <1-2000> dst-ip
no filter acl ace ip <1-2048> <1-2000> ip-frag-flag
no filter acl ace ip <1-2048> <1-2000> ip-options
no filter acl ace ip <1-2048> <1-2000> ip-protocol-type
no filter acl ace ip <1-2048> <1-2000> src-ip
no filter acl ace ip <1-2048> <1-2000> routed-only
no filter acl ace ip <1-2048> <1-2000>
Specifies the ACE ID.
Specifies the ACL ID.
phbcs0
phbcs1
phbaf11
phbaf12
phbaf13
phbcs2
phbaf21
phbaf22
phbaf23
phbcs3
phbaf31
phbaf32
phbaf33
phbcs4
phbaf41
phbaf42
phbaf43
phbcs5
phbcs6
phbef
phbcs7
a.b.c.d
[w.x.y.z-p.q.r.s]
[l.m.n.o/mask]
[a.b.c.d/len]
(1-256)
icmp
tcp
udp
ipsecesp
ipsecah
ospf
vrrp
undefined
a.b.c.d
[w.x.y.z-p.q.r.s]
[l.m.n.o/mask]
[a.b.c.d/len]
None
Global Configuration
The routed-only parameter is not supported for multicast packets.