cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
487
Views
0
Helpful
13
Replies

ACL and Wildcard

kylehash
Beginner
Beginner

Wildcard defaulting to the first value in the range of the wildcard and not allowing for any other value.

 


The default value of 0 in the third octet worked, but no other value worked with the ACL rule in place. The wildcard mask should have allowed for all values (0 - 255).

 

Can anyone explain to me why this is happening on my Cisco 9300 switch

13 Replies 13

MHM Cisco World
VIP Mentor VIP Mentor
VIP Mentor

I need to see the ACL statement line you enter. 

And expected packet and expected results.

Also helpful is describing specific switch model, specific IOS being used and feature license(s).

permit 12.0.0.22 0.0.255.0 

The above is the command used

...check my comment 

 

I think you dont understand fully. the network range that i want to come across is 12.0.X.22 0.0.255.0 so the third octet will be the only one to change. I think I kinda know what the error is, and why that traffic cannot traverse the network.

The ACL should be written 

permit IP 12.0.0.22 0.0.255.0

That should allow that intresting traffic to come through. right now it is written permit 12.0.0.22 0.0.255.0 which is not doing anything or allowing anything.

check my comment ...

Ah, finally some additional information.

Yes, you can write an ACL ACE such as permit IP 12.0.0.22 0.0.255.0, but will it provide the results you desire?

That ACL should match:

12.0.0.22
12.0.1.22
12.0.2.22
.
.
12.0.254.22
12.0.255.22

Is that the results you desire and if so, not obtaining?

If your looking for the network prefix 12.0.0.0/16 that would be: 

permit IP 12.0.<0..255>.<0..255> 0.0.255.255 (as also described by @MHM Cisco World )

I am looking for the

12.0.0.22

12.0.1.22

12.0.2.22

....

12.0.254.22

and i am not obtaining it.

Ok then, post the actual ACL, in full, actual interface(s) config(s), src and dest packet IPs and expected flow for traffic through interface(s).

I can not post all that. 

Ok, no problem.

marce1000
VIP Mentor VIP Mentor
VIP Mentor

 

       - You may find this tool useful : https://cway.cisco.com/tools/accesslist/

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers