Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

What does this mean in a Cisco Switch Config?

Posted on 2013-12-23
3
Medium Priority
?
944 Views
Last Modified: 2013-12-23
We are upgrading from a 3550 to a 3750 switch, and the only thing in the config I don't understand is this.

3550
ip access-list extended CMP-NAT-ACL
 dynamic Cluster-HSRP deny   ip any any
 dynamic Cluster-NAT permit ip any any

Open in new window


If I try to enter it into the 3750 I get this error.
% Only one dynamic entry can be configured per ACL.

Open in new window

and the config is saved at this.
ip access-list extended CMP-NAT-ACL
 dynamic Cluster-HSRP deny   ip any any

Open in new window


What does this policy do?  What should it be?
0
Comment
Question by:pamsauto
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 15

Expert Comment

by:WalkaboutTigger
ID: 39736716
So the first place I would point you to is this Cisco article on HSRP with a 3560 switch -
http://www.cisco.com/en/US/docs/switches/lan/catalyst3560/software/release/12.2_52_se/configuration/guide/swhsrp.html

and its corresponding document for the 3750
http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_55_se/configuration/guide/swhsrp.html

Are you using HSRP?
0
 

Author Comment

by:pamsauto
ID: 39736727
We only have one internet connection, so I would say no to using HSRP.
0
 
LVL 15

Accepted Solution

by:
WalkaboutTigger earned 2000 total points
ID: 39736738
Then, in my opinion, you can completely ignore this bit of the configuration unless there are other bits of the ACL you need.

But if you're not using HSRP, you can ignore the dynamic entries listed in your question.
0

Featured Post

Looking for a new Web Host?

Lunarpages' assortment of hosting products and solutions ensure a perfect fit for anyone looking to get their vision or products to market. Our award winning customer support and 30-day money back guarantee show the pride we take in being the industry's premier MSP.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question