?
Solved

CISCO ASR 1001 ACL

Posted on 2014-11-13
3
Medium Priority
?
536 Views
Last Modified: 2014-11-17
Can the ASR 1001 Cisco router support  either reflective or CBAC access control lists?

If so, please provide a link to the configuration
0
Comment
Question by:sectel
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 30

Expert Comment

by:Predrag
ID: 40442175
ALL MANUALS Link

Cisco support says reflective ACL is not supported.
However, Manual - page 14 says CBAC ACL is supported.
Cisco IOS XE Security Configuration Guide: Securingthe Data Plane
Access Control Lists (ACLs); Firewalls: Context-Based Access Control (CBAC) and Zone-Based Firewall; Cisco IOS Intrusion Prevention System (IPS); Flexible Packet Matching; Unicast Reverse Path Forwarding (uRPF); Threat Information Distribution Protocol (TIDP) and TMS.
Access port manual ASR 1001
0
 
LVL 32

Accepted Solution

by:
harbor235 earned 2000 total points
ID: 40447966
Neither are supported;

ASR models do not support CBAC only the Zone Based Policy Firewall which is the only IOS based firewall that will continue to be developed. CBAC or Classic Cisco IOS Firewall is not going away but will cease to be developed.

I have researched the latest version of code and the features you ask about are not present.

http://tools.cisco.com/ITDIT/CFN/jsp/SearchBySoftware.jsp

harbor235 ;}
0
 

Author Closing Comment

by:sectel
ID: 40448307
Excellent response
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question