This topic describes how to configure extended ACLs on the Cisco 8000 Series Router to verify more than just the source address of packets by matching on attributes such as destination address, IP protocols, UDP or TCP port numbers, and DSCP.
Use this procedure to configure an extended ACL. Extended ACLs verify more than just the source address of the packets. Attributes such as destination address, specific IP protocols, UDP or TCP port numbers, DSCP, and so on are validated. Traffic is controlled by a comparison of the attributes stated in the ACL with those in the incoming or outgoing packets.