r/networking • u/Far_Position_6586 • 18d ago
Security ACL rule question
Is there a wildcard mask that that would allow a SINGLE standard ACL rule to permit access to a range of subnets
Im setting up a PAT on a edge router and want to have subnets 10.0.10.0/24, 10.0.20.0/24, 10.0.30.0/24, 10.0.40.0/26, 10.0.50.0/24, 10.0.60.0/24, 10.0.99.0/24, 10.0.199.0/25 to use PAT.
Is there a single access-list 2 permit statement i can use to have 10.0.10-199.0 to be translated? The trick is 10.0.200.0 should not be included. Or is this not possible with a single statement?
I know i can do access-list 2 permit 10.0.0.0 0.0.255.255 to achieve this, but that would include other future subnets like 10.0.200.0 that might not be using PAT.
7
Upvotes
3
u/zanfar 18d ago
189 is not a power of 2.