So let's begin by setting the scenerio. You have the following ACL:
show ip access-list EXAMPLE
Extended IP access list EXAMPLE
1 permit ip host 10.10.10.28 any
2 permit ip host 10.10.10.10 any
3 permit ip host 10.10.10.11 any
4 permit ip host 10.10.10.45 any
5 deny ip 10.10.10.0 0.0.0.255 any
10 permit tcp any host 192.168.10.4 eq smtp
And let's say that we now need to allow one additional host out. We could rewrite the ACL, but that could be a lot of work if its a long ACL. Any other options?
Yes, the resequence command can help. This command was introduced in IOS 12.2(14)S, and allows you to easily resequence an entire ACL.
ip access-list resequence EXAMPLE 10 10
This will renumber every line in the ACL starting with 10, and with an increment of 10 between each line. This is the default sequencing for an access-list where no sequence numbers are entered. The end result would be:
Extended IP access list EXAMPLE
10 permit ip host 10.10.10.28 any
20 permit ip host 10.10.10.10 any
30 permit ip host 10.10.10.11 any
40 permit ip host 10.10.10.45 any
50 deny ip 10.10.10.0 0.0.0.255 any
60 permit tcp any host 192.168.10.4 eq smtp
0 comments:
Post a Comment
Discuss this post!