<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACL duplicates removal in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/2928496#M149314</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I use a file to add ACL to my ASA. The file contains set of rules (both inbound and outbound traffic). I run this file on my ASA using &lt;STRONG&gt;conf net&lt;/STRONG&gt; command. Now because of a huge list (~1.7MB file) and having many duplicates the file takes longer time to execute. I want to remove these duplicate entries from the ASA and from the file. Is there any way (any script) to find out the duplicates and remove it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please find few examples for duplicate types which are there in on my ASA&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Exp 1.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;access-list NEW&amp;nbsp;extended permit tcp host 1.1.1.1 host 2.2.2.2 eq https&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;object-group network Cloud&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;network-object host 2.2.2.2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;access-list NEW&amp;nbsp;extended permit tcp host 1.1.1.1 object-group Cloud&amp;nbsp;eq https&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Exp 2.&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;STRONG&gt;access-list NEW&amp;nbsp;extended permit tcp 1.1.0.0 255.255.0.0 host 2.2.2.2 eq https&lt;/STRONG&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;STRONG&gt;access-list NEW&amp;nbsp;extended permit tcp host 1.1.1.23 host 2.2.2.2 eq https&lt;/STRONG&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Please help me to get this resolved.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Ashish&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:23:03 GMT</pubDate>
    <dc:creator>aashu21392</dc:creator>
    <dc:date>2019-03-12T08:23:03Z</dc:date>
    <item>
      <title>ACL duplicates removal</title>
      <link>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/2928496#M149314</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I use a file to add ACL to my ASA. The file contains set of rules (both inbound and outbound traffic). I run this file on my ASA using &lt;STRONG&gt;conf net&lt;/STRONG&gt; command. Now because of a huge list (~1.7MB file) and having many duplicates the file takes longer time to execute. I want to remove these duplicate entries from the ASA and from the file. Is there any way (any script) to find out the duplicates and remove it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please find few examples for duplicate types which are there in on my ASA&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Exp 1.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;access-list NEW&amp;nbsp;extended permit tcp host 1.1.1.1 host 2.2.2.2 eq https&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;object-group network Cloud&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;network-object host 2.2.2.2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;access-list NEW&amp;nbsp;extended permit tcp host 1.1.1.1 object-group Cloud&amp;nbsp;eq https&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Exp 2.&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;STRONG&gt;access-list NEW&amp;nbsp;extended permit tcp 1.1.0.0 255.255.0.0 host 2.2.2.2 eq https&lt;/STRONG&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;STRONG&gt;access-list NEW&amp;nbsp;extended permit tcp host 1.1.1.23 host 2.2.2.2 eq https&lt;/STRONG&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Please help me to get this resolved.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Ashish&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/2928496#M149314</guid>
      <dc:creator>aashu21392</dc:creator>
      <dc:date>2019-03-12T08:23:03Z</dc:date>
    </item>
    <item>
      <title>Hi Ashu,</title>
      <link>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/2928497#M149316</link>
      <description>&lt;P&gt;Hi Ashu,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Unfortunately there is no such command on cisco ASA which can help you find duplicate ACL's.&lt;/P&gt;
&lt;P&gt;This is more of a manual work that needs to be done and is very important for ASA's improved performance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;However, you can try and use "Notepad++" where you can try and find the duplicate ACL's but again it will just point to the duplicate ACL but removal will again be manual.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;Pulkit&lt;/P&gt;
&lt;P&gt;_&lt;/P&gt;
&lt;P&gt;Pulkit&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 07:56:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/2928497#M149316</guid>
      <dc:creator>Pulkit Saxena</dc:creator>
      <dc:date>2016-10-12T07:56:12Z</dc:date>
    </item>
    <item>
      <title>Thank Pulkit</title>
      <link>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/2928498#M149317</link>
      <description>&lt;P&gt;Thank Pulkit&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As a said above I run this from a file. So I guess i need to find a script for this and edit the file accordingly and the run it on ASA for the removal.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ashish&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 09:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/2928498#M149317</guid>
      <dc:creator>aashu21392</dc:creator>
      <dc:date>2016-10-12T09:11:09Z</dc:date>
    </item>
    <item>
      <title>Ashish,</title>
      <link>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/2928499#M149318</link>
      <description>&lt;P&gt;Ashish,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;That will be great if you could find such script, please do share the same too bu creating your own document as that can help in lot of such scenarios.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;Pulkit&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 11:57:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/2928499#M149318</guid>
      <dc:creator>Pulkit Saxena</dc:creator>
      <dc:date>2016-10-12T11:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Ashish,</title>
      <link>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/3828005#M149319</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=e31Uz46AKn0" target="_blank"&gt;https://www.youtube.com/watch?v=e31Uz46AKn0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;A utility with which you can optimize the access list. There is a search function for conflicting rules. Designed for routers, but there is a way to use for ASA lists.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 12:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-duplicates-removal/m-p/3828005#M149319</guid>
      <dc:creator>GSA</dc:creator>
      <dc:date>2019-03-28T12:23:41Z</dc:date>
    </item>
  </channel>
</rss>

