Access-list match

Unanswered Question
Jun 15th, 2010
User Badges:


If access-list configured to match the packets used for NAT is as follows

ip access-list ext abcd

permit ip any

Which packets will be matched ?

If wild card mask  is things are normal.

please share the experiene.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Richard Burts Tue, 06/15/2010 - 20:08
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN


As you should be aware in the wildcard mask a binary 0 is a bit that must match and a binary 1 is a bit that may vary.

So in your mask of the first 3 octets must match exactly (it must be 10.1.1). The mask of the fourth octet has a single binary 1. It may help to write out the 4 octet in binary ( 00100000). So for this mask there are exactly 2 values of the address that will match the mask. These values are and

As your comment indicates this mask is quite unusual in an access list. It is much more common to have the mask be the inverse of common subnet masks (such as the mask .31 which is the inverse of mask 224).




This Discussion