Hi,
I was reading up on some ACL stuff, and came across this info from Cisco, regarding ACLs, and I cant quite get my head around it:
"In an IP extended ACL (both named and numbered), a Layer 4 system-defined mask cannot precede a Layer 3 user-defined mask. For example, a Layer 4 system-defined mask such as permit tcp any any or deny udp any any cannot precede a Layer 3 user-defined mask such as permit ip 10.1.1.1 any. If you configure this combination, the ACL is not configured. All other combinations of system-defined and user-defined masks are allowed in security ACLs. "
I think it has to do with what they refer to as "masks", especially system-defined and user-defined masks. What part of the ACL is what they call a mask? is the system defined the ANY part of it, or am i missing something here?
And i take it, that this information regarding ACLs also cover routers?
This is the full URL:
http://www.cisco.com/en/US/docs/switches/lan/catalyst2950/software/release/12.1_9_ea1/configuration/guide/swacl.html#wp1044050