<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL ACE change implementations in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763222#M1031193</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I stand corrected...my ip address change was to the ip address for each associated network-object host.  So with such change would the associated interface have to be rebound/executed to activate the change:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eg. fw# access-group acl-dmz4 in interface dmz4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or would it be in effect immediately after the change of the ip address of the associated network objects?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Jun 2007 18:54:54 GMT</pubDate>
    <dc:creator>michaelm18x</dc:creator>
    <dc:date>2007-06-08T18:54:54Z</dc:date>
    <item>
      <title>ACL ACE change implementations</title>
      <link>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763218#M1031095</link>
      <description>&lt;P&gt;On ASA5520 with 7.2(2) does WRITE MEMORY command apply changes made in NAMES and/or associated outlined ACL/ACE/OBJECTGROUPS or is re-entry of any associated access-group command such as below required?  If re-entry required, should NO paramenter be entered for related access-group command prior to re-entry of associated access-group command:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;access-group acl-dmz1 in interface dmz1&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763218#M1031095</guid>
      <dc:creator>michaelm18x</dc:creator>
      <dc:date>2019-03-11T10:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: ACL ACE change implementations</title>
      <link>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763219#M1031114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not quite sure what you are asking...&lt;/P&gt;&lt;P&gt;The Name, ACL, etc. commands are activated and running after you hit the "enter" key when entering them. This configuration is stored in the "running-config" file.&lt;/P&gt;&lt;P&gt;Typing "Write Memory" just saves the "running-config" file to NVRAM, "startup-config", so when you reboot the device it reads the new configuration. &lt;/P&gt;&lt;P&gt;This is helpful in that if you enter a wrong command, and lose all access to the device, you can reboot and recover to a "pre-change" condition.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Russ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 15:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763219#M1031114</guid>
      <dc:creator>rsmith</dc:creator>
      <dc:date>2007-06-08T15:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: ACL ACE change implementations</title>
      <link>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763220#M1031153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Issue was that I performed ip address changes on several devices in NAMES area related to subnet relocations and associated ACLs.  After it was confirmed that communication to new subnet was working, I was later informed that it was not and that this was possibly due to me not properly applying the change.  But startup-config comparisons of my change vs. updated change do not show any coding differences.  In addition, I am not being told exactly what I missed.  Therefore I can only deduct that I may have missed the rebinding of the related access-group to its interface, thinking that this make the change effective.  Is this a fair assumption?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 15:44:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763220#M1031153</guid>
      <dc:creator>michaelm18x</dc:creator>
      <dc:date>2007-06-08T15:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: ACL ACE change implementations</title>
      <link>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763221#M1031172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have not implemented any NAMES configuration, but I believe from the documentation that the NAMES table is separate from the configuration. Below is what I found in the command reference, and the URL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear configure name - Clears the list of names from the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;names - Enables the association of a name with an IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show running-config name - Displays the names associated with an IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa71/command/reference/no_711.html#wp1607336" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa71/command/reference/no_711.html#wp1607336&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 15:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763221#M1031172</guid>
      <dc:creator>rsmith</dc:creator>
      <dc:date>2007-06-08T15:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: ACL ACE change implementations</title>
      <link>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763222#M1031193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I stand corrected...my ip address change was to the ip address for each associated network-object host.  So with such change would the associated interface have to be rebound/executed to activate the change:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eg. fw# access-group acl-dmz4 in interface dmz4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or would it be in effect immediately after the change of the ip address of the associated network objects?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 18:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763222#M1031193</guid>
      <dc:creator>michaelm18x</dc:creator>
      <dc:date>2007-06-08T18:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: ACL ACE change implementations</title>
      <link>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763223#M1031209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since you just changed the IP address of the object (network-object host x.x.x.x or network object "net_address" "mask"), those changes should be immediate. The ACL's read the object, so it should pick up the new IP entered. You should not need to remove and re-install the access-group command.&lt;/P&gt;&lt;P&gt;Your original issue regarding access may be in another area? (routes? NAT?)&lt;/P&gt;&lt;P&gt;Here is a URL re:Object Groups. It does not provide much more on the issue, though:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800d641d.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800d641d.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 19:21:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-ace-change-implementations/m-p/763223#M1031209</guid>
      <dc:creator>rsmith</dc:creator>
      <dc:date>2007-06-08T19:21:56Z</dc:date>
    </item>
  </channel>
</rss>

