Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ACL and subnet mask


Do you know why Cisco keeps invert subnet masks (example:

It would simpler and safer to use a number to define a mask (example: - normal or -invert => 8), no?




  • WAN Routing and Switching

Re: ACL and subnet mask

Because it is a wildcard, not a mask.

a mask must be contiguous, a wild card need not be. Using them opposite makes that a little less confusing.

I also suspect that when initially coding, it may have been more efficient somehow to use them this way round.


New Member

Re: ACL and subnet mask

Thanks for your answer, i think it is more for a backward compatibily, to keep the same syntax on

all the IOSs.

For example, The Juniper and the vyatta routers use only a number for the mask (or the invert mask which only exist on Cisco)




Re: ACL and subnet mask

Using a number for the wildcard on an ACL would either make it more difficult or very awkward to some creative stuff with ACLs.

Take a position where you have a VERY structured IP addressing scheme based on, and you use the middle two octets to signify where the network is, and what type of network.

Using the high half of the second octet is noth. low half south, and use use even numbers for private networks, and odd for public. The third octed being odd means it is a wireless network.

You want to permit private wireless in the south.

Thats 10.0xxxxxx0.xxxxxxx1.don't care

or acce 10 pe ip simple all those condidtions in one line of an access list.

TBH I quite like it as it is, but I have been working with it for a number of years so am familiar. What this all means is that I can see that it is a mask, and that it is legit (mask must be contiguous so allowed values are 128 192 224 240 248 252 254 and 255) or that is is a wild card. The way it gets presented makes it obvious as well. is *clearly* a mask. is clearly a wild card, as the bits that are a 1 in the wild card are zero in the "address".

t may look confusing, but once you get the hang, it makes sense,


This widget could not be displayed.