Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

How to configure an inverse mask for ACLs


Masks are used with IP addresses in IP Access Control Lists (ACLs) to specify what should be permitted and denied.

Masks to configure IP addresses on interfaces start with 255 and have the large values on the left side (for example, IP address with a mask).

Masks for IP ACLs are the reverse (for example, mask This is sometimes called an inverse mask or a wildcard mask. When the value of the mask is broken down into binary (0s and 1s), the results determine which address bits are to be considered in processing the traffic. A 0 indicates that the address bits must be considered (exact match). A 1 in the mask is a "don't care."

The ACL inverse mask is determined by subtracting the normal mask from

For more information, refer to the Masks section of the Configuring IP Access Lists document.

Type of Filtering

Access lists / Packet filtering

Version history
Revision #:
1 of 1
Last update:
‎06-22-2009 04:07 PM
Updated by:
Labels (1)
Everyone's tags (3)