Networking-Blog

My WordPress Blog

Cisco Access-List Resequence Numbers

Cisco Named Access-List resequence numbers after removing a rule.

eg :

Cisco#show ip access-lists WANIncoming
!
Extended IP access list WANIncoming
10 permit ip host 1.1.1.1 any (243750 matches)
20 permit ip 2.2.2.8 0.0.0.7 any (982563 matches)
30 permit esp host 2.2.2.222 any (169532251 matches)
40 permit udp host 2.2.2.222 any eq isakmp (9864 matches)
50 permit udp host 2.2.2..30 any eq ntp (15 matches)
60 permit udp host 2.2.2.31 any eq ntp (15 matches)
70 permit udp host 194.72.6.57 eq domain any (87 matches)
80 permit udp host 194.73.82.242 eq domain any (9 matches)
90 permit icmp host 2.2.2.222 any (6 matches)
100 permit icmp any any administratively-prohibited
110 permit icmp any any echo-reply (7015 matches)
120 permit icmp any any packet-too-big
130 permit icmp any any time-exceeded (1044 matches)
140 permit icmp any any traceroute
150 permit icmp any any unreachable (774 matches)
180 deny ip any any log (6452 matches)

config t
ip access-list resequence WANIncoming 10 10

This will re-order to sequence no. to start from 10 and increment by 10.

Should look like this:

Cisco#show ip access-lists WANIncoming
!
Extended IP access list WANIncoming
10 permit ip host 1.1.1.1 any (243750 matches)
20 permit ip 2.2.2.8 0.0.0.7 any (982563 matches)
30 permit esp host 2.2.2.222 any (169532251 matches)
40 permit udp host 2.2.2.222 any eq isakmp (9864 matches)
50 permit udp host 2.2.2..30 any eq ntp (15 matches)
60 permit udp host 2.2.2.31 any eq ntp (15 matches)
70 permit udp host 194.72.6.57 eq domain any (87 matches)
80 permit udp host 194.73.82.242 eq domain any (9 matches)
90 permit icmp host 2.2.2.222 any (6 matches)
100 permit icmp any any administratively-prohibited
110 permit icmp any any echo-reply (7015 matches)
120 permit icmp any any packet-too-big
130 permit icmp any any time-exceeded (1044 matches)
140 permit icmp any any traceroute
150 permit icmp any any unreachable (774 matches)
160 deny ip any any log (6452 matches)
!
!
e.g :

config t
ip access-list resequence WANIncoming 10 10

This will re-order to sequence no. to start from 5 and increment by 5.

Cisco#show ip access-lists WANIncoming
!
Extended IP access list WANIncoming
5 permit ip host 1.1.1.1 any (243750 matches)
10 permit ip 2.2.2.8 0.0.0.7 any (982563 matches)
15 permit esp host 2.2.2.222 any (169532251 matches)
20 permit udp host 2.2.2.222 any eq isakmp (9864 matches)
25 permit udp host 2.2.2..30 any eq ntp (15 matches)
30 permit udp host 2.2.2.31 any eq ntp (15 matches)
35 permit udp host 194.72.6.57 eq domain any (87 matches)
40 permit udp host 194.73.82.242 eq domain any (9 matches)
45 permit icmp host 2.2.2.222 any (6 matches)
50 permit icmp any any administratively-prohibited
55 permit icmp any any echo-reply (7015 matches)
60 permit icmp any any packet-too-big
65 permit icmp any any time-exceeded (1044 matches)
70 permit icmp any any traceroute
75 permit icmp any any unreachable (774 matches)
80 deny ip any any log (6452 matches)

You can also remove rules from the ACL by sequence numbers :
!
config t

ip access-list extended WANIncoming
no 50
no 60

Cisco ASA FTP Access-List

ASA Version 7.2(2)
!
hostname ASA-AIP-CLI
domain-name corp.com
enable password WwXYvtKrnjXqGbu1 encrypted
names
!
interface Ethernet0/0
 nameif Outside
 security-level 0
 ip address 192.168.1.2 255.255.255.0
!
interface Ethernet0/1
 nameif Inside
 security-level 100
ip address 10.1.1.1 255.255.255.0
!
interface Ethernet0/2
 nameif DMZ
  security-level 50
  ip address 172.16.1.12 255.255.255.0
!
interface Ethernet0/3
 no nameif
 no security-level
 no ip address
!
interface Management0/0
  no nameif
 no security-level
 no ip address
!

!--- Output is suppressed.


!--- Permit inbound FTP control traffic. 

access-list 100 extended permit tcp any host 192.168.1.5 eq ftp

!--- Permit inbound FTP data traffic.

access-list 100 extended permit tcp any host 192.168.1.5 eq ftp-data
!

!--- Command to redirect the FTP traffic received on IP 192.168.1.5
!--- to IP 172.16.1.5.

static (DMZ,outside) 192.168.1.5 172.16.1.5 netmask 255.255.255.255
access-group 100 in interface outside
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512

policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect netbios
  inspect rsh
  inspect rtsp
  inspect skinny
  inspect esmtp
  inspect sqlnet
  inspect sunrpc
  inspect tftp
  inspect sip
  inspect xdmcp
!

!--- This command tells the device to
!--- use the "global_policy" policy-map on all interfaces.

service-policy global_policy global

LAN Outbound FTP Access : 
access-list inside extended permit tcp host 10.1.1.254 any eq ftp Create Object group in order to tidy config : object-group service Bluecoatbypass tcp description Bypass for bluecoat server port-object eq echo port-object eq irc port-object eq ftp-data port-object range 3389 3389 port-object eq domain port-object range 8080 8080 port-object eq pop3 port-object eq ftp port-object eq www port-object eq https port-object eq 1935 port-object eq ssh ! Create Access-list : access-list inside extended permit tcp host 10.1.1.254 any object-group Bluecoatbypass
Verify : show access-list | grep ftp | grep 10.1.1.254 show service-policy inspect ftp show service-policy global

Cisco Named Access-List WAN

ip access-list extended Wan_Traffic_in
remark ISP_DHCP
permit udp any any eq bootpc bootps
remark DENY_Spam_Email_Ip_Addresses
deny   ip host 80.237.152.41 any
deny   ip host 210.193.7.241 any
deny   ip host 194.146.227.72 any
deny   ip host 218.107.207.123 any
deny   ip host 80.189.90.17 any
deny   ip host 58.215.255.74 any
deny   ip host 60.191.248.102 any
deny   ip host 209.202.164.112 any
deny   ip host 68.142.212.70 any
deny   ip host 195.95.24.94 any
deny   ip host 208.74.44.15 any
deny   ip host 62.1.216.170 any
deny   ip host 68.180.151.74 any
deny   ip host 204.244.135.1 any
deny   ip host 12.154.55.204 any
deny   ip host 209.237.150.20 any
deny   ip host 72.52.206.162 any
deny   ip host 59.106.72.230 any
deny   ip host 213.92.32.230 any
deny   ip host 87.24.42.59 any
deny   ip host 82.98.86.172 any
remark DENY_IP_Spoofing_Addresses
deny   ip 10.0.0.0 0.255.255.255 any
deny   ip 127.0.0.0 0.255.255.255 any
deny   ip 172.16.0.0 0.0.255.255 any
deny   ip 192.168.0.0 0.0.255.255 any
deny   ip 224.0.0.0 0.255.255.255 any
deny   ip 240.0.0.0 0.255.255.255 any
remark DENY_Traffic
deny   tcp any host 86.17.130.81 eq telnet
deny   udp any host 86.17.130.81 eq 135
deny   udp any host 86.17.130.81 eq netbios-ns
deny   udp any host 86.17.130.81 eq netbios-ss
deny   ip host 0.0.0.0 any
remark ICMP
permit icmp any host 86.17.130.81 administratively-prohibited
permit icmp host 80.74.17.9 host 86.17.130.81 echo
permit icmp any host 86.17.130.81 echo-reply
permit icmp any host 86.17.130.81 unreachable
permit icmp any host 86.17.130.81 time-exceeded
permit icmp any host 86.17.130.81 traceroute
remark MTU_Path_Discovery
permit icmp any host 86.17.130.81 packet-too-big
remark IPSEC
permit udp any host 86.17.130.81 eq non500-isakmp
permit udp any host 86.17.130.81 eq isakmp
permit esp any host 86.17.130.81
permit ahp any host 86.17.130.81
permit tcp any host 86.17.130.81 eq 10000
remark VPN_PPTP
permit tcp any host 86.17.130.81 eq 1723
remark GRE
permit gre any host 86.17.130.81
remark RDP
permit tcp any host 86.17.130.81 eq 3390
remark FTP
permit tcp any host 86.17.130.81 eq 121
permit tcp any host 86.17.130.81 eq 47000
permit tcp any host 86.17.130.81 eq 47001
permit tcp any host 86.17.130.81 eq 47002
permit tcp any host 86.17.130.81 eq 47003
permit tcp any host 86.17.130.81 eq 47004
permit tcp any host 86.17.130.81 eq 47005
permit tcp any host 86.17.130.81 eq 47006
permit tcp any host 86.17.130.81 eq 47007
permit tcp any host 86.17.130.81 eq 47008
permit tcp any host 86.17.130.81 eq 47009
permit tcp any host 86.17.130.81 eq 47010
remark SSH
permit tcp any host 86.17.130.81 eq 22
remark NTP
permit udp host 193.201.200.74 host 86.17.130.81 eq ntp
remark UTORRENT_LIMEWIRE
permit tcp any host 86.17.130.81 eq 50518
deny   ip any any log
!
interface fa0/0
ip access-group Wan_Traffic_in in

Cisco Named Access-List LAN

ip access-list extended Lan_Traffic_Out
deny   ip host 192.168.2.4 host 24.199.192.15
deny   ip host 192.168.2.4 host 216.27.56.6
deny   ip host 192.168.2.4 host 207.38.11.174
remark HTTP
permit tcp host 192.168.2.4 any eq www
remark HTTPS
permit tcp host 192.168.2.4 any eq 443
remark AAA_Radius
permit udp host 192.168.2.4 host 192.168.2.1 range 1645 1646
remark ICMP
permit icmp host 192.168.2.4 any
remark DNS
permit udp host 192.168.2.4 any eq domain
permit tcp host 192.168.2.4 any eq domain
remark SSH
permit tcp host 192.168.2.4 any eq 22
remark TFTP
permit udp host 192.168.2.4 any eq tftp
remark TELNET
permit tcp host 192.168.2.4 any eq telnet
remark NTP
permit udp 192.168.2.0 0.0.0.15 host 192.168.2.1 eq ntp
remark SMTP
permit tcp host 192.168.2.4 any eq smtp
remark MICROSOFT VPN
permit tcp host 192.168.2.4 any eq 1723 log
remark GRE (GENERIC ROUTING ENCAPSULATION)
permit gre host 192.168.2.4 any log
remark RDP
permit tcp host 192.168.2.4 any eq 3389
remark VNC
permit tcp host 192.168.2.4 any eq 5900
remark NETFLOW_ANALYZER
permit udp host 192.168.2.4 host 192.168.2.1 eq 9996
remark SNMP
permit udp host 192.168.2.4 host 192.168.2.1 eq snmp
remark SNMP_TRAPS
permit udp host 192.168.2.4 host 192.168.2.1 eq snmptrap
remark SYSLOG
permit udp host 192.168.2.4 host 192.168.2.1 eq syslog
remark MSN MSSENGER
permit tcp host 192.168.2.4 207.46.106.0 0.0.0.255 eq 1863
permit tcp host 192.168.2.4 207.46.107.0 0.0.0.255 eq 1863
permit tcp host 192.168.2.4 207.46.110.0 0.0.0.255 eq 1863
permit tcp host 192.168.2.4 207.46.124.0 0.0.0.255 eq 1863
permit tcp host 192.168.2.4 207.46.125.0 0.0.0.255 eq 1863
permit tcp host 192.168.2.4 64.4.34.0 0.0.0.255 eq 1863
permit tcp host 192.168.2.4 64.4.36.0 0.0.0.255 eq 1863
permit tcp host 192.168.2.4 64.4.37.0 0.0.0.255 eq 1863
permit tcp host 192.168.2.4 64.4.50.0 0.0.0.255 eq 1863
permit tcp host 192.168.2.4 65.54.171.0 0.0.0.255 eq 1863
permit tcp host 192.168.2.4 65.54.228.0 0.0.0.255 eq 1863
remark SPOTIFY
permit tcp host 192.168.2.4 host 78.31.8.14 eq 4070
permit tcp host 192.168.2.4 host 78.31.8.31 eq 4070
permit tcp host 192.168.2.4 host 78.31.8.16 eq 4070
permit tcp host 192.168.2.4 host 78.31.8.17 eq 4070
permit tcp host 192.168.2.4 host 78.31.8.18 eq 4070
permit tcp host 192.168.2.4 host 78.31.8.19 eq 4070
remark LIMEWIRE
permit tcp host 192.168.2.4 any eq 6346 log
remark UTORRENT
permit tcp host 192.168.2.4 any range 1024 65535
permit udp host 192.168.2.4 any range 1024 65535
remark PRINTER
permit tcp host 192.168.2.4 host 192.168.5.2 eq 9100
remark DENY_TRAFFIC
deny   ip any any log
!
interface vlan 1
ip access-group Lan_Traffic_Out in