Cisco 7604 Configuration Manual page 245

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Chapter 13
Identifying Traffic with Access Lists
After optimization:
Adjacency—If rule x is adjacent to rule y, rule y is merged up with rule x.
Before optimization:
After optimization:
Overlap—If rule x overlaps rule y, rule y is merged up with rule x.
Before optimization:
After optimization:
Note
Two redundant/overlapping rules cannot be merged if there exists a conflicting rule in the access list
located in between the two rules.
Permit/Deny—If rule x overlaps with rule y and rule z and rule y has an opposite permission/action,
rule x cannot be merged with rule z even though both rules have the same permission/action.
Before optimization:
After optimization:
Logging (default, disable keywords)—If rule x with a "log default" keyword overlaps with rule y
with a "log disable" keyword, rule x can be merged with rule y only if both rules have a "permit"
action.
Before optimization:
After optimization:
Before optimization:
After optimization:
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
access-list test extended permit udp 10.1.1.0 255.255.255.0 any [rule x]
access-list test extended permit ip 10.1.1.0 255.255.255.128 any [rule x]
access-list test extended permit ip 10.1.1.128 255.255.255.128 any [rule y]
access-list test extended permit ip 10.1.1.0 255.255.255.0 any [rule x]
access-list test extended permit tcp any any range 50 100 [rule x]
access-list test extended permit tcp any any range 60 120 [rule y]
access-list test extended permit tcp any any range 50 120 rule x]
access-list test extended permit tcp any any range 50 100 [rule x]
access-list test extended deny tcp any any range 80 130 [rule y]
access-list test extended permit tcp any any range 60 120 [rule z]
access-list test extended permit tcp any any range 50 100 [rule x]
access-list test extended deny tcp any any range 80 130 [rule y]
access-list test extended permit tcp any any range 60 120 [rule z]
access-list test extended permit tcp any any range 50 100 log default [rule x]
access-list test extended permit tcp any any range 80 130 log disable [rule y]
access-list test extended permit tcp any any range 50 130 log default [rule x]
access-list test extended deny tcp any any range 50 100 log default [rule x]
access-list test extended deny tcp any any range 80 130 log disable [rule y]
access-list test extended deny tcp any any range 50 100 log default [rule x]
Access List Group Optimization
13-19

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents