ACLs use wildcard masks instead of subnet masks. A wildcard mask is the inverse of a subnet mask. Where a subnet mask has s, a wildcard has s, and vice versa.
- Subnet mask becomes wildcard
- Subnet mask becomes wildcard
In a wildcard mask, means "must match" and means "don't care". So says "match the first octets exactly, ignore the last octet."