Monday
Hi Team,
I want to create a filter ACL that matches all traffic types, but I´m not able to configure an ACE with an any condition.
For the moment, it doesn't matter what I'm going to use it for. Maybe it could be useful to count all packets on a port, or to mirror all traffic to a probe.
Is it possible?
Cheers!!
EF
8 hours ago
Hello, a true “match everything” ACE, the usual approach is to leave the match criteria unrestricted rather than looking for a literal any condition. For example, on platforms that support it, an IPv4 ACL entry such as permit ip any any represents all IPv4 traffic; some platforms also require a separate IPv6 entry if you want all traffic.
Tuesday
Yes, it is entirely possible to create an ACL that matches all traffic types by using an "any" condition—such as permit ip any any in standard network operating systems like Cisco IOS. If you are encountering configuration errors, it typically comes down to platform-specific syntax, applying the rule to the wrong ACL type (e.g., mixing Layer 2 and Layer 3), or hardware limitations on certain ports. Double-check your device's configuration guide for extended or IP-named ACL syntax to ensure the universal matching statement is permitted in your specific context.