Users Guide

Table Of Contents
out — Apply the ACL to outgoing traffic.
Default Not configured
Command Mode
INTERFACE
CONTROL-PLANE
Usage Information Use this command in the CONTROL-PLANE mode to apply a control-plane ACL. Control-plane ACLs are only
applied on the ingress traffic. By default, the control-plane ACL is applied to the front-panel ports as well as the
management port.The no version of this command deletes the IPv4 ACL configuration.
Example
OS10(conf-if-eth1/1/8)# ip access-group testgroup in
Example (Control-
plane ACL)
OS10# configure terminal
OS10(config)# control-plane
OS10(config-control-plane)# ip access-group aaa-cp-acl in
Supported
Releases
10.2.0E or later; 10.4.1 or later (control-plane ACL)
ip access-list
Creates an IP access list to filter based on an IP address.
Syntax
ip access-list access-list-name
Parameters access-list-name — Enter the name of an IPv4 access list. A maximum of 140 characters.
Default Not configured
Command Mode CONFIGURATION
Usage Information None
Example
OS10(config)# ip access-list acl1
Supported
Releases
10.2.0E or later
ip as-path access-list
Create an AS-path ACL filter for BGP routes using a regular expression.
Syntax
ip as-path access-list name {deny | permit} regexp-string
Parameters
name — Enter an access list name.
deny | permit — Reject or accept a matching route.
regexp-string — Enter a regular expression string to match an AS-path route attribute.
Defaults Not configured
Command Mode CONFIGURATION
Usage Information
You can specify an access-list filter on inbound and outbound BGP routes. The ACL filter consists of regular
expressions. If a regular expression matches an AS path attribute in a BGP route, the route is rejected or
accepted. The AS path does not contain the local AS number. The no version of this command removes a single
access list entry if you specify deny and a regexp. Otherwise, the entire access list is removed.
The question mark (?) character is not supported in the regular expressions. All other special characters are
supported. When you are using
backslash(\) or double quotes (”) in the regular expression, precede
these characters with
backslash(\). For example, enter \\ or \”.
Access Control Lists 1041