372Configuring and Managing Security ACLs

Modifying an Existing Security ACL

You can use the modify editbuffer-indexportion of the set security acl command to modify an active security ACL. For example, suppose the ACL acl-111currently blocks some packets from IP address 192.168.254.12 with the mask 0.0.0.255 and you want to change the ACL to permit all packets from this address. Follow these steps:

1To display all committed security ACLs, type the following command:

23x0# show security acl info all

ACL information for all

set security acl ip acl-111 (hits #4 0)

----------------------------------------------------

1.deny IP source IP 192.168.254.12 0.0.0.255 destination IP

any

2.permit IP source IP 192.168.253.11 0.0.0.0 destination IP

any

set security acl ip acl-2 (hits #1 0)

----------------------------------------------------

1.permit L4 Protocol 115 source IP 192.168.1.11 0.0.0.0 destination IP 192.168.1.15 0.0.0.0 precedence 0 tos 0 enable-hits

2To modify the first ACE in acl-111, type the following commands:

23x0# set security acl ip acl-111 permit 192.168.254.12 0.0.0.0 modify 1

23x0# commit security acl acl-111 success: change accepted.

3To view the results, type the following command:

23x0# show security acl info all

ACL information for all

set security acl ip acl-111 (hits #4 0)

----------------------------------------------------

1.permit IP source IP 192.168.254.12 0.0.0.0 destination IP

any

2.permit IP source IP 192.168.253.11 0.0.0.0 destination IP

any

set security acl ip acl-2 (hits #1 0)

----------------------------------------------------

1.permit L4 Protocol 115 source IP 192.168.1.11 0.0.0.0 destination IP 192.168.1.15 0.0.0.0 precedence 0 tos 0 enable-hits

320657-A

Page 372
Image 372
Nortel Networks 2300 manual Modifying an Existing Security ACL