access-list permit_access_internet extended deny ip 10.0.70.0 255.255.255.0 any
access-group permit_access_internet in interface inside
定义to_internet应用到inside的入口方向:
access-group to_internet in interface inside
先deny单个ip,然后permit其他ip:
access-list to_internet extended deny ip any 173.16.0.250 255.255.255.255
access-list to_internet extended permit ip any 173.16.0.0 255.255.255.0
做acl ,然后应用于接口就好