查看acl
使用 show run
查看,acl没有显示出序号
Switch#show run
interface Vlan123
ip address 172.16.123.10 255.255.255.0
ip access-group deny_by_123 in
ip access-list extended deny_by_123
permit ip 172.16.123.0 0.0.0.255 10.11.12.0 0.0.0.255
deny ip 172.16.123.0 0.0.0.255 192.168.0.0 0.0.255.255
deny ip 172.16.123.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip any any
使用 show ip access-lists ***(acl名称)
显示出来了acl序号
Switch#show ip access-lists deny_by_123
Extended IP access list deny_by_123
10 permit ip 172.16.123.0 0.0.0.255 10.11.12.0 0.0.0.255 (7641239 matches)
20 deny ip 172.16.123.0 0.0.0.255 10.0.0.0 0.255.255.255 (17278 matches)
30 deny ip 172.16.123.0 0.0.0.255 192.168.0.0 0.0.255.255 (33106 matches)
123 permit ip any any (7791230 matches)
查看版本 show version
思科ios版本为12.3以前的版本,show ip access-lists 不会显示有acl序号,这是旧版ios的特性。
这种没有acl序号的思科旧设备,删除acl可以正常一条一条删除,但是添加acl时,是按照你输入的先后顺序排列; 要记得把 permit ip any any 放在最后输入。