Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX 525 - adding a line to existing access list

Been a while since I had to config a pix. When and access-list exists and is attached to an interface with the access-group command, what are the rules for adding a line to the list? Can I just add a line - where in the list does it end up? There is no deny all explicitly configured in the access-list.

1 ACCEPTED SOLUTION

Accepted Solutions
Hall of Fame Super Blue

Re: PIX 525 - adding a line to existing access list

Hi

On pix v6.x you can delete an individual line within the access-list and it won't delete the access-list.

Jon

5 REPLIES
Hall of Fame Super Blue

Re: PIX 525 - adding a line to existing access list

Hi

you don't say which version of software on Pix but assuming v6.x onwards.

Do a "sh access-list name_of_access-list"

When you view the output it will have line numbers included. So to insert a rule to allow icmp from any to any at line 2 of your access-list

access-list name_of_access-list line 2 permit icmp any any

HTH

Jon

New Member

Re: PIX 525 - adding a line to existing access list

And if there is already a line 2 it slides all the other rules down one?

Hall of Fame Super Blue

Re: PIX 525 - adding a line to existing access list

Yes, exactly.

New Member

Re: PIX 525 - adding a line to existing access list

The rules are: add a line OK. Delete a line = bad. It will wipe out your ACL and remove the access-group from the interface.

Copy your existing ACL into a text editor and add the additional line just to be safe. it is okay to copy everything back, it won't affect anything this way. And there is a Deny all at the end but you may not see it.

Hall of Fame Super Blue

Re: PIX 525 - adding a line to existing access list

Hi

On pix v6.x you can delete an individual line within the access-list and it won't delete the access-list.

Jon

2412
Views
5
Helpful
5
Replies