cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1110
Views
0
Helpful
2
Replies

ACL Sequence Number Help

kevin.hu
Level 3
Level 3

Hi,

We have an ISR 3825 with the latest 12.4T running as our perimeter router.  We use sequence numbers to organize the ingress ACL.  For example, 200 to 2000 sequence numbers are to block prefixes from xxx country, 2100 to 4000 sequence numbers are for yyy country, etc.  Configuration is saved.

After I rebooted the router, I noticed that all my sequence numbers were resetted to default!  I found this documentation in CCO:

"Sequence numbers are not nvgened. That is, the sequence numbers themselves are not saved. In the event that the system is reloaded, the configured sequence numbers revert to the default sequence starting number and increment. The function is provided for backward compatibility with software releases that do not support sequence numbering."

It is hard for me to accept this answer.  Do you guys also see this issue?  Is there a way to retain your own sequence number organization after the reboot?

Thanks.

1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

kevin.hu wrote:

Hi,

We have an ISR 3825 with the latest 12.4T running as our perimeter router.  We use sequence numbers to organize the ingress ACL.  For example, 200 to 2000 sequence numbers are to block prefixes from xxx country, 2100 to 4000 sequence numbers are for yyy country, etc.  Configuration is saved.

After I rebooted the router, I noticed that all my sequence numbers were resetted to default!  I found this documentation in CCO:

"Sequence numbers are not nvgened. That is, the sequence numbers themselves are not saved. In the event that the system is reloaded, the configured sequence numbers revert to the default sequence starting number and increment. The function is provided for backward compatibility with software releases that do not support sequence numbering."

It is hard for me to accept this answer.  Do you guys also see this issue?  Is there a way to retain your own sequence number organization after the reboot?

Thanks.

Kevin

Sequence numbers are only used to allow you to insert additional lines without having to redo the whole access-list. If you want to organize your acl you should look at object-groups which your version of IOS should support. Object-groups would allow you to have groups of IPs per country and then use them in your acl -

12.4T IOS object-groups

Jon

View solution in original post

2 Replies 2

Jon Marshall
Hall of Fame
Hall of Fame

kevin.hu wrote:

Hi,

We have an ISR 3825 with the latest 12.4T running as our perimeter router.  We use sequence numbers to organize the ingress ACL.  For example, 200 to 2000 sequence numbers are to block prefixes from xxx country, 2100 to 4000 sequence numbers are for yyy country, etc.  Configuration is saved.

After I rebooted the router, I noticed that all my sequence numbers were resetted to default!  I found this documentation in CCO:

"Sequence numbers are not nvgened. That is, the sequence numbers themselves are not saved. In the event that the system is reloaded, the configured sequence numbers revert to the default sequence starting number and increment. The function is provided for backward compatibility with software releases that do not support sequence numbering."

It is hard for me to accept this answer.  Do you guys also see this issue?  Is there a way to retain your own sequence number organization after the reboot?

Thanks.

Kevin

Sequence numbers are only used to allow you to insert additional lines without having to redo the whole access-list. If you want to organize your acl you should look at object-groups which your version of IOS should support. Object-groups would allow you to have groups of IPs per country and then use them in your acl -

12.4T IOS object-groups

Jon

Thanks Jon.  It is exactly what I am looking for.

Kevin

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card