[c-nsp] non-CIDR netmasks in ACLs

Rick Ernst ernst at easystreet.com
Tue May 17 13:05:43 EDT 2005


I have a set of IP addresses (outside of my control) that need to be passed
through an ACL.  Instead of being in a convenient block, they are in the
form of 1.2.x.4, with x being 96-111.

IOS allows me to add an ACL like:
  access-list 100 permit ip 1.2.96.4 0.0.15.0

However.... "What will it break"?  From the viewpoint of simply tweaking
the bits, it looks valid, but...  At the same time, I'd rather have a
single ACL statement for 16 hosts, not 16 lines.

Thanks,
Rick






More information about the cisco-nsp mailing list