Access lists use a reverse mask to define the network. So, your access list commands should look like the following:
access-list 172 deny ip any 172.20.0.0 0.0.3.255
access-list 172 permit ip any any
Then apply it to the interface.
I also find it helpful to place a remark at the top as a...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.