Reader Tip - Resequence Entries in an ACL

Document

May 6, 2011 7:35 AM
Mar 30th, 2011

/* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-qformat:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin-top:0in; mso-para-margin-right:0in; mso-para-margin-bottom:10.0pt; mso-para-margin-left:0in; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:"Times New Roman"; mso-fareast-theme-font:minor-fareast; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin;}

This month's tip from Kasiraman Eljay explains how the "ip access-list resequence" command can be very helpful.  Thanks to Kasiraman for sending in his favorite tip!

I found the “ip access-list resequence” command for an ACL to be very helpful. Most of the time network operators try to remove the ACL, edit the entries in notepad, and then paste the ACL back in via the CLI.  Resequencing the ACL can reduce the overhead to accomplish this when specific edits are needed.

Take for example the following ACL to illustrate the concept:

Router_#sh ip access-lists TEST

Extended IP access list TEST

2 permit ip host 10.10.10.1 host 10.10.10.2

3 permit ip host 10.10.10.3 host 10.10.10.4

Now let’s assume that an entry is needed between the two existing lines in the ACL.

To do this we need to have a gap in the middle so let’s assign a new set of sequence numbers.

Router_(config)#ip access-list resequence TEST 10 10

This starts the first entry with a sequence number of 10 and increments all new lines by 10. The result is:

Router_#sh ip access-lists TEST

Extended IP access list TEST

10 permit ip host 10.10.10.1 host 10.10.10.2

20 permit ip host 10.10.10.3 host 10.10.10.4

Now it’s easy to insert a new ACL entry with a sequence number of say 15 that would fall between the two existing entries in the TEST access-list.

The Configuration URL for reference is:

http://www.cisco.com/en/US/docs/ios/12_2s/feature/guide/fsaclseq.html

Subscribe to the TS Newsletter today at:

https://tools.cisco.com/gdrp/coiga/showsurvey.do?surveyCode=474&keyCode=123668_1

Overall Rating: 5 (3 ratings)
george.johnston Fri, 05/06/2011 - 07:35

One caveat to keep in mind with this is if you use remarks in your ACL for documenting entries, they get screwed up using this technique.

Actions

Login or Register to take actions

This Document

Posted March 30, 2011 at 7:08 AM
Updated April 28, 2011 at 3:37 AM
Stats:
Comments:1 Overall Rating:5
Views:8879 Contributors:1
Shares:0

Related Content

 

Documents Leaderboard

Rank Username Points
1
ashirkar
164
2
TCC_2
118
3
Marwan ALshawi
97
4
Maher Abdelshkour
84
5
Jason Short
40
Rank Username Points
ashirkar
5
Juri Jestin
5