Cisco Access-List Resequence Numbers
Cisco Named Access-List resequence numbers after removing a rule.
eg :
Cisco#show ip access-lists WANIncoming
!
Extended IP access list WANIncoming
10 permit ip host 1.1.1.1 any (243750 matches)
20 permit ip 2.2.2.8 0.0.0.7 any (982563 matches)
30 permit esp host 2.2.2.222 any (169532251 matches)
40 permit udp host 2.2.2.222 any eq isakmp (9864 matches)
50 permit udp host 2.2.2..30 any eq ntp (15 matches)
60 permit udp host 2.2.2.31 any eq ntp (15 matches)
70 permit udp host 194.72.6.57 eq domain any (87 matches)
80 permit udp host 194.73.82.242 eq domain any (9 matches)
90 permit icmp host 2.2.2.222 any (6 matches)
100 permit icmp any any administratively-prohibited
110 permit icmp any any echo-reply (7015 matches)
120 permit icmp any any packet-too-big
130 permit icmp any any time-exceeded (1044 matches)
140 permit icmp any any traceroute
150 permit icmp any any unreachable (774 matches)
180 deny ip any any log (6452 matches)
config t
ip access-list resequence WANIncoming 10 10
This will re-order to sequence no. to start from 10 and increment by 10.
Should look like this:
Cisco#show ip access-lists WANIncoming
!
Extended IP access list WANIncoming
10 permit ip host 1.1.1.1 any (243750 matches)
20 permit ip 2.2.2.8 0.0.0.7 any (982563 matches)
30 permit esp host 2.2.2.222 any (169532251 matches)
40 permit udp host 2.2.2.222 any eq isakmp (9864 matches)
50 permit udp host 2.2.2..30 any eq ntp (15 matches)
60 permit udp host 2.2.2.31 any eq ntp (15 matches)
70 permit udp host 194.72.6.57 eq domain any (87 matches)
80 permit udp host 194.73.82.242 eq domain any (9 matches)
90 permit icmp host 2.2.2.222 any (6 matches)
100 permit icmp any any administratively-prohibited
110 permit icmp any any echo-reply (7015 matches)
120 permit icmp any any packet-too-big
130 permit icmp any any time-exceeded (1044 matches)
140 permit icmp any any traceroute
150 permit icmp any any unreachable (774 matches)
160 deny ip any any log (6452 matches)
!
!
e.g :
config t
ip access-list resequence WANIncoming 10 10
This will re-order to sequence no. to start from 5 and increment by 5.
Cisco#show ip access-lists WANIncoming
!
Extended IP access list WANIncoming
5 permit ip host 1.1.1.1 any (243750 matches)
10 permit ip 2.2.2.8 0.0.0.7 any (982563 matches)
15 permit esp host 2.2.2.222 any (169532251 matches)
20 permit udp host 2.2.2.222 any eq isakmp (9864 matches)
25 permit udp host 2.2.2..30 any eq ntp (15 matches)
30 permit udp host 2.2.2.31 any eq ntp (15 matches)
35 permit udp host 194.72.6.57 eq domain any (87 matches)
40 permit udp host 194.73.82.242 eq domain any (9 matches)
45 permit icmp host 2.2.2.222 any (6 matches)
50 permit icmp any any administratively-prohibited
55 permit icmp any any echo-reply (7015 matches)
60 permit icmp any any packet-too-big
65 permit icmp any any time-exceeded (1044 matches)
70 permit icmp any any traceroute
75 permit icmp any any unreachable (774 matches)
80 deny ip any any log (6452 matches)
You can also remove rules from the ACL by sequence numbers :
!
config t
ip access-list extended WANIncoming
no 50
no 60