How to configure an inverse mask for ACLs


Wed, 07/22/2009 - 19:37
Jun 22nd, 2009
User Badges:
  • Gold, 750 points or more


Masks are used with IP addresses in IP Access Control Lists (ACLs) to specify what should be permitted and denied.

Masks to configure IP addresses on interfaces start with 255 and have the large values on the left side (for example, IP address with a mask).

Masks for IP ACLs are the reverse (for example, mask This is sometimes called an inverse mask or a wildcard mask. When the value of the mask is broken down into binary (0s and 1s), the results determine which address bits are to be considered in processing the traffic. A 0 indicates that the address bits must be considered (exact match). A 1 in the mask is a "don't care."

The ACL inverse mask is determined by subtracting the normal mask from

For more information, refer to the Masks section of the Configuring IP Access Lists document.

Type of Filtering

Access lists / Packet filtering



This Document

Related Content