Skip to content

Access List

Access lists are security and traffic control mechanisms that filter network traffic based on various criteria including source and destination IP addresses, ports, protocols, and other packet characteristics. They serve as fundamental building blocks for implementing security policies, Quality of Service (QoS), and network access control by permitting or denying traffic that matches specific conditions. Access lists can be applied to interfaces, routing protocols, and various network services to enforce granular traffic filtering and policy enforcement throughout the network infrastructure.

Diagram
NameTypeConstraintMandatoryDefault Value
access_listsClass[access_lists]No

access_lists (iosxe.devices.configuration)

Section titled “access_lists (iosxe.devices.configuration)”
NameTypeConstraintMandatoryDefault Value
standardList[standard]No
extendedList[extended]No
role_basedList[role_based]No
as_pathList[as_path]No

standard (iosxe.devices.configuration.access_lists)

Section titled “standard (iosxe.devices.configuration.access_lists)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
entriesList[entries]No

extended (iosxe.devices.configuration.access_lists)

Section titled “extended (iosxe.devices.configuration.access_lists)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
entriesList[entries]No

role_based (iosxe.devices.configuration.access_lists)

Section titled “role_based (iosxe.devices.configuration.access_lists)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
entriesList[entries]No

as_path (iosxe.devices.configuration.access_lists)

Section titled “as_path (iosxe.devices.configuration.access_lists)”
NameTypeConstraintMandatoryDefault Value
numberIntegermin: 1, max: 500Yes
entriesList[entries]No

entries (iosxe.devices.configuration.access_lists.standard)

Section titled “entries (iosxe.devices.configuration.access_lists.standard)”
NameTypeConstraintMandatoryDefault Value
sequenceIntegerYes
remarkStringNo
actionChoicedeny, permitNo
prefixIPNo
prefix_maskIPNo
anyBooleantrue, falseNo
hostIPNo
logBooleantrue, falseNo

entries (iosxe.devices.configuration.access_lists.extended)

Section titled “entries (iosxe.devices.configuration.access_lists.extended)”
NameTypeConstraintMandatoryDefault Value
sequenceIntegerYes
remarkStringNo
actionChoicedeny, permitNo
protocolAnyChoice[ahp, eigrp, esp, gre, icmp, igmp, ip, ipinip, nos, object-group, ospf, pcp, pim, tcp, udp] or Integer[min: 0, max: 255] or String[Regex: ^.*[\$\%]\{.*$]No
service_object_groupStringNo
sourceClass[source]No
destinationClass[destination]No
tcp_flagsAnyList[Choice[ack, fin, psh, rst, syn, urg]]No
establishedBooleantrue, falseNo
fragmentsBooleantrue, falseNo
dscpAnyChoice[af11, af12, af13, af21, af22, af23, af31, af32, af33, af41, af42, af43, cs1, cs2, cs3, cs4, cs5, cs6, cs7, default, dscp, ef, precedence] or Integer[min: 0, max: 63] or String[Regex: ^.*[\$\%]\{.*$]No
precedenceAnyChoice[critical, flash, flash-override, immediate, internet, network, priority, routine] or Integer[min: 0, max: 7] or String[Regex: ^.*[\$\%]\{.*$]No
tosAnyChoice[max-reliability, max-throughput, min-delay, min-monetary-cost, normal] or Integer[min: 0, max: 15] or String[Regex: ^.*[\$\%]\{.*$]No
icmp_message_typeAnyString or Integer[min: 0, max: 255] or String[Regex: ^.*[\$\%]\{.*$]No
icmp_message_codeIntegermin: 0, max: 255No
logBooleantrue, falseNo
log_inputBooleantrue, falseNo

entries (iosxe.devices.configuration.access_lists.role_based)

Section titled “entries (iosxe.devices.configuration.access_lists.role_based)”
NameTypeConstraintMandatoryDefault Value
sequenceIntegermin: 1, max: 2147483647Yes
remarkStringNo
actionChoicedeny, permitNo
protocolAnyChoice[ahp, eigrp, esp, gre, icmp, igmp, ip, ipinip, nos, object-group, ospf, pcp, pim, tcp, udp] or Integer[min: 0, max: 255] or String[Regex: ^.*[\$\%]\{.*$]No
tcp_flagsAnyList[Choice[ack, fin, psh, rst, syn, urg]]No
establishedBooleantrue, falseNo
fragmentsBooleantrue, falseNo
dscpAnyChoice[af11, af12, af13, af21, af22, af23, af31, af32, af33, af41, af42, af43, cs1, cs2, cs3, cs4, cs5, cs6, cs7, default, dscp, ef, precedence] or Integer[min: 0, max: 63] or String[Regex: ^.*[\$\%]\{.*$]No
precedenceAnyChoice[critical, flash, flash-override, immediate, internet, network, priority, routine] or Integer[min: 0, max: 7] or String[Regex: ^.*[\$\%]\{.*$]No
tosAnyChoice[max-reliability, max-throughput, min-delay, min-monetary-cost, normal] or Integer[min: 0, max: 15] or String[Regex: ^.*[\$\%]\{.*$]No
optionAnyChoice[add-ext, any-options, com-security, dps, encode, eool, ext-ip, ext-security, finn, imitd, lsr, mtup, mtur, no-op, nsapa, record-route, router-alert, sdb, security, ssr, stream-id, timestamp, traceroute, ump, visa, zsu] or Integer[min: 0, max: 255] or String[Regex: ^.*[\$\%]\{.*$]No
time_rangeStringNo
logBooleantrue, falseNo
log_inputBooleantrue, falseNo
match_allListChoice[+ack, +fin, +psh, +rst, +syn, +urg, -ack, -fin, -psh, -rst, -syn, -urg]No
match_anyListChoice[+ack, +fin, +psh, +rst, +syn, +urg, -ack, -fin, -psh, -rst, -syn, -urg]No

entries (iosxe.devices.configuration.access_lists.as_path)

Section titled “entries (iosxe.devices.configuration.access_lists.as_path)”
NameTypeConstraintMandatoryDefault Value
actionChoicepermit, denyYes
regexStringYes

source (iosxe.devices.configuration.access_lists.extended.entries)

Section titled “source (iosxe.devices.configuration.access_lists.extended.entries)”
NameTypeConstraintMandatoryDefault Value
prefixIPNo
prefix_maskIPNo
anyBooleantrue, falseNo
hostIPNo
object_groupStringNo
fqdn_groupStringNo
port_typeChoiceequal, greater_than, lesser_than, rangeNo
portAnyInteger or String[Regex: ^.*[\$\%]\{.*$] or StringNo
additional_equal_portsListIntegerNo
port_range_fromIntegerNo
port_range_toIntegerNo

destination (iosxe.devices.configuration.access_lists.extended.entries)

Section titled “destination (iosxe.devices.configuration.access_lists.extended.entries)”
NameTypeConstraintMandatoryDefault Value
prefixIPNo
prefix_maskIPNo
anyBooleantrue, falseNo
hostIPNo
object_groupStringNo
fqdn_groupStringNo
port_typeChoiceequal, greater_than, lesser_than, rangeNo
portAnyInteger or String[Regex: ^.*[\$\%]\{.*$] or StringNo
additional_equal_portsListIntegerNo
port_range_fromIntegerNo
port_range_toIntegerNo

By defining granular rules for traffic filtering, Access Lists enhance network security, control resource access, and ensure efficient network operation. They are crucial for implementing security policies at the network edge and within internal segments.

  • ACL Name (Standard/Extended)
  • Entry Sequence Number
  • Action (Permit/Deny)
  • Source IP Address/Network
  • Source Wildcard Mask
  • Any Source (Standard ACLs)
  • Destination IP Address/Network (Extended ACLs)
  • Destination Wildcard Mask (Extended ACLs)
  • Protocol (Extended ACLs)
  • Port Numbers (Extended ACLs)
  • FQDN Group (Extended ACLs)
  • Established Connections (Extended ACLs)
  • Log Input (Extended ACLs)
  • Time Range (Role-based ACLs)
  • Remark (Role-based ACLs)

You can use these Access List parameters to define precise traffic filtering rules for your network devices. Customize the type, entries, and matching criteria to fit your network’s security and operational needs. Adjusting these parameters lets you tailor access control for your environment.

  • The established attribute matches TCP packets with the ACK or RST bits set and is only applicable to entries with protocol: tcp.
  • Extended ACL entries support two logging attributes: log enables basic logging of packets matching the ACL entry, while log_input includes input interface information in log messages. These attributes are mutually exclusive.

Port Attribute Dependencies:

  • When defining port-specific attributes on extended ACL entries, the port_type attribute must be explicitly defined with an appropriate value:
    • If using port_range_from or port_range_to, port_type must be set to range
    • If using port, port_type must be set to one of: equal, greater_than, or lesser_than
    • If using additional_equal_ports, port_type must be set to equal
  • This requirement applies to both source and destination port configurations
  • Failure to define port_type when using port attributes will result in validation errors

FQDN Group References:

  • Extended ACL entries support fqdn_group as a source or destination address type, referencing a previously defined FQDN object group (object_groups_fqdn)
  • fqdn_group is mutually exclusive with other address types (prefix, any, host, object_group) within the same source or destination block

The following configuration describes how to set up Standard and Extended IP Access Lists on an IOS-XE device. It lists how to define rules for permitting and denying traffic based on various criteria, including port-based filtering.

ip access-list standard StandardAccessList1
10 permit 10.0.0.0 0.0.0.255
20 permit 20.0.0.0 0.0.0.255
!
ip access-list standard StandardAccessList2
10 permit any
20 deny any log
!
ip access-list extended ExtendedAccessList1
10 permit ip any any
20 deny tcp any any syn ack
30 deny tcp any any eq 80
40 permit tcp any range 8000 8080 any
50 deny tcp any any gt 1024
60 permit tcp any any eq 443 www 8443
70 permit tcp any eq 22 830 32000 any
!
ip access-list extended ExtendedAccessList2
10 deny ip any any log-input
!
ip access-list extended ExtendedAccessList3
10 permit tcp any any established
!
ip access-list extended ExtendedAccessList4
10 permit tcp any 192.168.1.0 0.0.0.255 eq 443
!
object-group fqdn TRUSTED_DOMAINS
pattern *.example.com
!
ip access-list extended ExtendedAccessList5
10 permit tcp fqdn-group TRUSTED_DOMAINS any eq 443
20 deny ip any fqdn-group TRUSTED_DOMAINS
!
time-range BUSINESS_HOURS
periodic weekdays 9:00 to 17:00
!
ip access-list role-based RoleBasedAccessList1
10 permit tcp time-range BUSINESS_HOURS
20 deny ip
!
ip access-list role-based RoleBasedAccessList2
10 remark Allow traffic from trusted sources
20 permit ip
iosxe:
devices:
- name: Device1
configuration:
access_lists:
standard:
- name: StandardAccessList1
entries:
- sequence: 10
action: permit
prefix: 10.0.0.0
prefix_mask: 0.0.0.255
- sequence: 20
action: permit
prefix: 20.0.0.0
prefix_mask: 0.0.0.255
# Standard ACL using 'any' to match all source addresses
- name: StandardAccessList2
entries:
- sequence: 10
action: permit
any: true
- sequence: 20
action: deny
any: true
log: true
extended:
- name: ExtendedAccessList1
entries:
# Basic permit all IP traffic
- sequence: 10
action: permit
protocol: ip
source:
any: true
destination:
any: true
# Deny TCP traffic with SYN and ACK flags set
- sequence: 20
action: deny
protocol: tcp
tcp_flags: [syn, ack]
source:
any: true
destination:
any: true
# Deny HTTP traffic (port 80) - demonstrates 'equal' port_type
- sequence: 30
action: deny
protocol: tcp
source:
any: true
destination:
any: true
port_type: equal
port: 80
# Permit traffic from ports 8000-8080 - demonstrates 'range' port_type
- sequence: 40
action: permit
protocol: tcp
source:
any: true
port_type: range
port_range_from: 8000
port_range_to: 8080
destination:
any: true
# Deny traffic to ports greater than 1024 - demonstrates 'greater_than' port_type
- sequence: 50
action: deny
protocol: tcp
source:
any: true
destination:
any: true
port_type: greater_than
port: 1024
# Permit HTTPS and HTTP traffic - demonstrates multiple destination equal ports
- sequence: 60
action: permit
protocol: tcp
source:
any: true
destination:
any: true
port_type: equal
port: 443
additional_equal_ports: [80, 8443]
# Permit traffic from multiple source ports - demonstrates multiple source equal ports
- sequence: 70
action: permit
protocol: tcp
source:
any: true
port_type: equal
port: 22
additional_equal_ports: [830, 32000]
destination:
any: true
# Extended ACL using 'log_input' to log with interface information
- name: ExtendedAccessList2
entries:
- sequence: 10
action: deny
protocol: ip
source:
any: true
destination:
any: true
log_input: true
# Extended ACL using 'established' to permit return traffic
- name: ExtendedAccessList3
entries:
- sequence: 10
action: permit
protocol: tcp
source:
any: true
destination:
any: true
established: true
# Extended ACL using destination prefix to filter by destination network
- name: ExtendedAccessList4
entries:
- sequence: 10
action: permit
protocol: tcp
source:
any: true
destination:
prefix: 192.168.1.0
prefix_mask: 0.0.0.255
port_type: equal
port: 443
# Extended ACL using FQDN groups for source and destination
- name: ExtendedAccessList5
entries:
- sequence: 10
action: permit
protocol: tcp
source:
fqdn_group: TRUSTED_DOMAINS
destination:
any: true
port_type: equal
port: 443
- sequence: 20
action: deny
protocol: ip
source:
any: true
destination:
fqdn_group: TRUSTED_DOMAINS
# Role-based ACL using 'time_range' for time-based access control
role_based:
- name: RoleBasedAccessList1
entries:
- sequence: 10
action: permit
protocol: tcp
time_range: BUSINESS_HOURS
- sequence: 20
action: deny
protocol: ip
# Role-based ACL using 'remark' for documentation
- name: RoleBasedAccessList2
entries:
- sequence: 10
remark: Allow traffic from trusted sources
- sequence: 20
action: permit
protocol: ip

AS-path access lists are used to filter BGP routes based on autonomous system path attributes. They use regular expressions to match patterns in the AS-path of BGP routes, enabling precise control over which routes are accepted or advertised based on the autonomous systems they traverse.

The following configuration shows AS-path access lists used for BGP route filtering:

ip as-path access-list 100 permit ^65000_
ip as-path access-list 200 deny _65001$
ip as-path access-list 200 permit .*
iosxe:
devices:
- name: router1
configuration:
access_lists:
as_path:
- number: 100
entries:
- action: permit
regex: "^65000_"
- number: 200
entries:
- action: deny
regex: "_65001$"
- action: permit
regex: ".*"

Access lists are security and traffic control mechanisms that filter network traffic based on various criteria including source and destination IP addresses, ports, protocols, and other packet characteristics. They serve as fundamental building blocks for implementing security policies, Quality of Service (QoS), and network access control by permitting or denying traffic that matches specific conditions. Access lists can be applied to interfaces, routing protocols, and various network services to enforce granular traffic filtering and policy enforcement throughout the network infrastructure.

Diagram
NameTypeConstraintMandatoryDefault Value
access_listsClass[access_lists]No

access_lists (iosxe.devices.configuration)

Section titled “access_lists (iosxe.devices.configuration)”
NameTypeConstraintMandatoryDefault Value
standardList[standard]No
extendedList[extended]No
role_basedList[role_based]No
as_pathList[as_path]No

standard (iosxe.devices.configuration.access_lists)

Section titled “standard (iosxe.devices.configuration.access_lists)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
entriesList[entries]No

extended (iosxe.devices.configuration.access_lists)

Section titled “extended (iosxe.devices.configuration.access_lists)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
entriesList[entries]No

role_based (iosxe.devices.configuration.access_lists)

Section titled “role_based (iosxe.devices.configuration.access_lists)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
entriesList[entries]No

as_path (iosxe.devices.configuration.access_lists)

Section titled “as_path (iosxe.devices.configuration.access_lists)”
NameTypeConstraintMandatoryDefault Value
numberIntegermin: 1, max: 500Yes
entriesList[entries]No

entries (iosxe.devices.configuration.access_lists.standard)

Section titled “entries (iosxe.devices.configuration.access_lists.standard)”
NameTypeConstraintMandatoryDefault Value
sequenceIntegerYes
remarkStringNo
actionChoicedeny, permitNo
prefixIPNo
prefix_maskIPNo
anyBooleantrue, falseNo
hostIPNo
logBooleantrue, falseNo

entries (iosxe.devices.configuration.access_lists.extended)

Section titled “entries (iosxe.devices.configuration.access_lists.extended)”
NameTypeConstraintMandatoryDefault Value
sequenceIntegerYes
remarkStringNo
actionChoicedeny, permitNo
protocolAnyChoice[ahp, eigrp, esp, gre, icmp, igmp, ip, ipinip, nos, object-group, ospf, pcp, pim, tcp, udp] or Integer[min: 0, max: 255] or String[Regex: ^.*[\$\%]\{.*$]No
service_object_groupStringNo
sourceClass[source]No
destinationClass[destination]No
tcp_flagsAnyList[Choice[ack, fin, psh, rst, syn, urg]]No
establishedBooleantrue, falseNo
fragmentsBooleantrue, falseNo
dscpAnyChoice[af11, af12, af13, af21, af22, af23, af31, af32, af33, af41, af42, af43, cs1, cs2, cs3, cs4, cs5, cs6, cs7, default, dscp, ef, precedence] or Integer[min: 0, max: 63] or String[Regex: ^.*[\$\%]\{.*$]No
precedenceAnyChoice[critical, flash, flash-override, immediate, internet, network, priority, routine] or Integer[min: 0, max: 7] or String[Regex: ^.*[\$\%]\{.*$]No
tosAnyChoice[max-reliability, max-throughput, min-delay, min-monetary-cost, normal] or Integer[min: 0, max: 15] or String[Regex: ^.*[\$\%]\{.*$]No
icmp_message_typeAnyString or Integer[min: 0, max: 255] or String[Regex: ^.*[\$\%]\{.*$]No
icmp_message_codeIntegermin: 0, max: 255No
logBooleantrue, falseNo
log_inputBooleantrue, falseNo

entries (iosxe.devices.configuration.access_lists.role_based)

Section titled “entries (iosxe.devices.configuration.access_lists.role_based)”
NameTypeConstraintMandatoryDefault Value
sequenceIntegermin: 1, max: 2147483647Yes
remarkStringNo
actionChoicedeny, permitNo
protocolAnyChoice[ahp, eigrp, esp, gre, icmp, igmp, ip, ipinip, nos, object-group, ospf, pcp, pim, tcp, udp] or Integer[min: 0, max: 255] or String[Regex: ^.*[\$\%]\{.*$]No
tcp_flagsAnyList[Choice[ack, fin, psh, rst, syn, urg]]No
establishedBooleantrue, falseNo
fragmentsBooleantrue, falseNo
dscpAnyChoice[af11, af12, af13, af21, af22, af23, af31, af32, af33, af41, af42, af43, cs1, cs2, cs3, cs4, cs5, cs6, cs7, default, dscp, ef, precedence] or Integer[min: 0, max: 63] or String[Regex: ^.*[\$\%]\{.*$]No
precedenceAnyChoice[critical, flash, flash-override, immediate, internet, network, priority, routine] or Integer[min: 0, max: 7] or String[Regex: ^.*[\$\%]\{.*$]No
tosAnyChoice[max-reliability, max-throughput, min-delay, min-monetary-cost, normal] or Integer[min: 0, max: 15] or String[Regex: ^.*[\$\%]\{.*$]No
optionAnyChoice[add-ext, any-options, com-security, dps, encode, eool, ext-ip, ext-security, finn, imitd, lsr, mtup, mtur, no-op, nsapa, record-route, router-alert, sdb, security, ssr, stream-id, timestamp, traceroute, ump, visa, zsu] or Integer[min: 0, max: 255] or String[Regex: ^.*[\$\%]\{.*$]No
time_rangeStringNo
logBooleantrue, falseNo
log_inputBooleantrue, falseNo
match_allListChoice[+ack, +fin, +psh, +rst, +syn, +urg, -ack, -fin, -psh, -rst, -syn, -urg]No
match_anyListChoice[+ack, +fin, +psh, +rst, +syn, +urg, -ack, -fin, -psh, -rst, -syn, -urg]No

entries (iosxe.devices.configuration.access_lists.as_path)

Section titled “entries (iosxe.devices.configuration.access_lists.as_path)”
NameTypeConstraintMandatoryDefault Value
actionChoicepermit, denyYes
regexStringYes

source (iosxe.devices.configuration.access_lists.extended.entries)

Section titled “source (iosxe.devices.configuration.access_lists.extended.entries)”
NameTypeConstraintMandatoryDefault Value
prefixIPNo
prefix_maskIPNo
anyBooleantrue, falseNo
hostIPNo
object_groupStringNo
port_typeChoiceequal, greater_than, lesser_than, rangeNo
portAnyInteger or String[Regex: ^.*[\$\%]\{.*$] or StringNo
port_range_fromIntegerNo
port_range_toIntegerNo

destination (iosxe.devices.configuration.access_lists.extended.entries)

Section titled “destination (iosxe.devices.configuration.access_lists.extended.entries)”
NameTypeConstraintMandatoryDefault Value
prefixIPNo
prefix_maskIPNo
anyBooleantrue, falseNo
hostIPNo
object_groupStringNo
port_typeChoiceequal, greater_than, lesser_than, rangeNo
portAnyInteger or String[Regex: ^.*[\$\%]\{.*$] or StringNo
additional_equal_portsListIntegerNo
port_range_fromIntegerNo
port_range_toIntegerNo

By defining granular rules for traffic filtering, Access Lists enhance network security, control resource access, and ensure efficient network operation. They are crucial for implementing security policies at the network edge and within internal segments.

  • ACL Name (Standard/Extended)
  • Entry Sequence Number
  • Action (Permit/Deny)
  • Source IP Address/Network
  • Source Wildcard Mask
  • Destination IP Address/Network (Extended ACLs)
  • Destination Wildcard Mask (Extended ACLs)
  • Protocol (Extended ACLs)
  • Port Numbers (Extended ACLs)

You can use these Access List parameters to define precise traffic filtering rules for your network devices. Customize the type, entries, and matching criteria to fit your network’s security and operational needs. Adjusting these parameters lets you tailor access control for your environment.

Port Attribute Dependencies:

  • When defining port-specific attributes on extended ACL entries, the port_type attribute must be explicitly defined with an appropriate value:
    • If using port_range_from or port_range_to, port_type must be set to range
    • If using port, port_type must be set to one of: equal, greater_than, or lesser_than
    • If using additional_equal_ports (destination only), port_type must be set to equal
  • This requirement applies to both source and destination port configurations
  • Failure to define port_type when using port attributes will result in validation errors

The following configuration describes how to set up Standard and Extended IP Access Lists on an IOS-XE device. It lists how to define rules for permitting and denying traffic based on various criteria, including port-based filtering.

ip access-list standard StandardAccessList1
10 permit 10.0.0.0 0.0.0.255
20 permit 20.0.0.0 0.0.0.255
!
ip access-list extended ExtendedAccessList1
10 permit ip any any
20 deny tcp any any syn ack
30 deny tcp any any eq 80
40 permit tcp any range 8000 8080 any
50 deny tcp any any gt 1024
60 permit tcp any any eq 443 www 8443
iosxe:
devices:
- name: Device1
configuration:
access_lists:
standard:
- name: StandardAccessList1
entries:
- sequence: 10
action: permit
prefix: 10.0.0.0
prefix_mask: 0.0.0.255
- sequence: 20
action: permit
prefix: 20.0.0.0
prefix_mask: 0.0.0.255
extended:
- name: ExtendedAccessList1
entries:
# Basic permit all IP traffic
- sequence: 10
action: permit
protocol: ip
source:
any: true
destination:
any: true
# Deny TCP traffic with SYN and ACK flags set
- sequence: 20
action: deny
protocol: tcp
tcp_flags: [syn, ack]
source:
any: true
destination:
any: true
# Deny HTTP traffic (port 80) - demonstrates 'equal' port_type
- sequence: 30
action: deny
protocol: tcp
source:
any: true
destination:
any: true
port_type: equal
port: 80
# Permit traffic from ports 8000-8080 - demonstrates 'range' port_type
- sequence: 40
action: permit
protocol: tcp
source:
any: true
port_type: range
port_range_from: 8000
port_range_to: 8080
destination:
any: true
# Deny traffic to ports greater than 1024 - demonstrates 'greater_than' port_type
- sequence: 50
action: deny
protocol: tcp
source:
any: true
destination:
any: true
port_type: greater_than
port: 1024
# Permit HTTPS and HTTP traffic - demonstrates multiple equal ports
- sequence: 60
action: permit
protocol: tcp
source:
any: true
destination:
any: true
port_type: equal
port: 443
additional_equal_ports: [80, 8443]