Solved

How to remove rules on an extended access list without removing everything

Posted on 2009-04-10
2
813 Views
Last Modified: 2012-08-13
Is there a way to remove just one piece of an extended ACL without removing everything?

For example:

Extended IP access list 250
    10 permit ip 192.168.0.0 0.1.255.255 any (2 matches)
    20 permit ip 224.0.0.0 15.255.255.255 any
    30 permit ip 192.169.0.0 0.0.255.255 any
    40 deny ip any any log-input (143083 matches)

What if I only wanted to remove the "40 deny ip"? What will be the command?

This is on a 6500 chassis with sup 720.
0
Comment
Question by:typertec
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24118104
Like this:

conf t
ip access-list ext 250
no deny ip any any log-input
0
 
LVL 10

Accepted Solution

by:
atlas_shuddered earned 300 total points
ID: 24119029
A simpler way is to just use the line number

config t
ip access-list edt 250
no 10
no 30
no 40


etc.

You can use the same method to insert lines to an existing list:

20 permit ip 224.0.0.0 15.255.255.255 any
30 permit ip 192.169.0.0 0.0.255.255 any




0

Featured Post

Increase Agility with Enabled Toolchains

Connect your existing build, deployment, management, monitoring, and collaboration platforms. From Puppet to Chef, HipChat to Slack, ServiceNow to JIRA, Splunk to New Relic and beyond, hand off data between systems to engage the right people.

Connect with xMatters.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question