Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

FWSM ver 3.2 - No access-list line x doesn't work

Hi All,

I am trying to remove a line in a particular access-list configured in a FWSM module using this command "no access-list <acl> line 19 x x x x" but it doesn't work. See below:

FWSM/xxx03(config)# no access-list ?

configure mode commands/options:

  alert-interval  Specify the alert interval for generating syslog message

                  106001 which alerts that the system has reached a deny

                  flow maximum. If not specified, the default value is 300 sec

  deny-flow-max   Specify the maximum number of concurrent deny flows that can

                  be created. If not specified, the default value is 4096

How can I remove a line from the access-list without clearing the entire access-list?

Thanks in advance

  • Firewalling
3 REPLIES
New Member

FWSM ver 3.2 - No access-list line x doesn't work

You can remove one line instead of invisibility of this option. Type "no" and ACL entry which you want to delete.

New Member

FWSM ver 3.2 - No access-list line x doesn't work

Thanks Andrey.

You mean I should just type

" No access-list extended permit tcp object-group object-group object-group "

and it will work?

But why doesn't the IOS show it?

FWSM ver 3.2 - No access-list line x doesn't work

Hello Nirmal,

What Andrey suggested is correct, that is all you need.

Now on the last post you add it this:

No access-list extended permit tcp object-group object-group object-group

Everything is fine except the extended. you do not need that, so it would look like this example:

No access-list test permit tcp any any eq 80

That should take out from the access-list that particular line, now it is weard that when you do no access-list you do not get the word command ( witch is the name or number of the ACL) but lets give it a try with the command Andrey suggested and let see how it goes.

Please rate helpful posts.

Julio!!!!

Looking for some Networking Assistance? Contact me directly at jcarvaja@laguiadelnetworking.com I will fix your problem ASAP. Cheers, Julio Carvajal Segura http://laguiadelnetworking.com
767
Views
0
Helpful
3
Replies
This widget could not be displayed.