Configuring and Managing Security ACLs 373

Clearing Security ACLs from the Edit Buffer

Use the rollback command to clear changes made to the security ACL edit buffer since it was last committed. The ACL is rolled back to its state at the last commit command. For example, suppose you want to remove an ACE that you just created in the edit buffer for acl-111:

1To display the contents of all committed security ACLs, type the following command:

23x0# show security acl info all

ACL information for all

set security acl ip acl-111 (hits #4 0)

----------------------------------------------------

1.permit IP source IP 192.168.254.12 0.0.0.0 destination IP

any

2.permit IP source IP 192.168.253.11 0.0.0.0 destination IP

any

set security acl ip acl-2 (hits #1 0)

----------------------------------------------------

1.permit L4 Protocol 115 source IP 192.168.1.11 0.0.0.0 destination IP 192.168.1.15 0.0.0.0 precedence 0 tos 0 enable-hits

2To view a summary of the security ACLs for which you just created ACEs in the edit buffer, type the following command:

23x0# show security acl editbuffer

ACL edit-buffer table

ACL

Type

Status

-------------------------------

----

--------------

acl-a

IP

Not

committed

acl-111

IP

Not

committed

3To view details about these uncommitted ACEs, type the following command. The entire acl-111is displayed, including its committed ACEs.

23x0# show security acl info all editbuffer

ACL edit-buffer information for all

set security acl ip acl-111 (ACEs 3, add 3, del 0, modified 2)

----------------------------------------------------

1.permit IP source IP 192.168.254.12 0.0.0.0 destination IP

any

2.permit IP source IP 192.168.253.11 0.0.0.0 destination IP

any

3.deny SRC source IP 192.168.253.1 0.0.0.255

set security acl ip acl-a (ACEs 1, add 1, del 0, modified 0)

----------------------------------------------------

1. permit SRC source IP 192.168.1.1 0.0.0.0

Nortel WLAN Security Switch 2300 Series Configuration Guide

Page 373
Image 373
Nortel Networks 2300 manual Clearing Security ACLs from the Edit Buffer, 23x0# show security acl editbuffer