Solved

How to remove rules on an extended access list without removing everything

Posted on 2009-04-10
2
808 Views
Last Modified: 2012-08-13
Is there a way to remove just one piece of an extended ACL without removing everything?

For example:

Extended IP access list 250
    10 permit ip 192.168.0.0 0.1.255.255 any (2 matches)
    20 permit ip 224.0.0.0 15.255.255.255 any
    30 permit ip 192.169.0.0 0.0.255.255 any
    40 deny ip any any log-input (143083 matches)

What if I only wanted to remove the "40 deny ip"? What will be the command?

This is on a 6500 chassis with sup 720.
0
Comment
Question by:typertec
2 Comments
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24118104
Like this:

conf t
ip access-list ext 250
no deny ip any any log-input
0
 
LVL 10

Accepted Solution

by:
atlas_shuddered earned 300 total points
ID: 24119029
A simpler way is to just use the line number

config t
ip access-list edt 250
no 10
no 30
no 40


etc.

You can use the same method to insert lines to an existing list:

20 permit ip 224.0.0.0 15.255.255.255 any
30 permit ip 192.169.0.0 0.0.255.255 any




0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
connect poe switch to non poe switch 3 45
Alcatel Lucent OS6450 switch randomly reboots 4 52
configure ASA Vlan Interface 14 46
access vs trunk with voice vlan 2 20
I see many questions here on Experts Exchange regarding switch port configurations and trunks. This article is meant for beginners in the subject to help to get basic knowledge about Virtual Local Area Network (VLAN (http://en.wikipedia.org/wiki/Vir…
This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now