<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inactive ACL in ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inactive-acl-in-asa/m-p/2309366#M311168</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Essentially the &lt;STRONG&gt;"inactive"&lt;/STRONG&gt; means that the rule is configured on the ASA but its disabled and isnt used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is for example situation where you dont want to remove the ACL rule but just want to temporarily disable it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rule being greyed out in the ASDM means the same. Its present in the configurations but is disabled so the ASA should consider this rule when traffic is coming through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not really configured any ACL rules as &lt;STRONG&gt;"inactive"&lt;/STRONG&gt; myself. I tend to remove them completely and re-enter something if there is a need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the explanation of the parameter &lt;STRONG&gt;"inactive"&lt;/STRONG&gt; from the ASA Command Reference&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;inactive&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Optional)&amp;nbsp;&amp;nbsp;&amp;nbsp; Disables an ACE. To reenable it, enter the entire ACE without&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the inactive keyword. This feature lets you keep a record of an inactive&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACE in your configuration to make reenabling easier.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Oct 2013 17:51:09 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-10-10T17:51:09Z</dc:date>
    <item>
      <title>Inactive ACL in ASA</title>
      <link>https://community.cisco.com/t5/network-security/inactive-acl-in-asa/m-p/2309365#M311167</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ASDM&amp;nbsp; i see few ACL that are greyed out and have line on them.&lt;/P&gt;&lt;P&gt;On CLI i see those ACL&amp;nbsp; with&amp;nbsp; inactive at then end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to confirm why these ACL have inactive at then end?&lt;/P&gt;&lt;P&gt;Why they are greyed out in ASDM ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inactive-acl-in-asa/m-p/2309365#M311167</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T02:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Inactive ACL in ASA</title>
      <link>https://community.cisco.com/t5/network-security/inactive-acl-in-asa/m-p/2309366#M311168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Essentially the &lt;STRONG&gt;"inactive"&lt;/STRONG&gt; means that the rule is configured on the ASA but its disabled and isnt used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is for example situation where you dont want to remove the ACL rule but just want to temporarily disable it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rule being greyed out in the ASDM means the same. Its present in the configurations but is disabled so the ASA should consider this rule when traffic is coming through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not really configured any ACL rules as &lt;STRONG&gt;"inactive"&lt;/STRONG&gt; myself. I tend to remove them completely and re-enter something if there is a need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the explanation of the parameter &lt;STRONG&gt;"inactive"&lt;/STRONG&gt; from the ASA Command Reference&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;inactive&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Optional)&amp;nbsp;&amp;nbsp;&amp;nbsp; Disables an ACE. To reenable it, enter the entire ACE without&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the inactive keyword. This feature lets you keep a record of an inactive&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACE in your configuration to make reenabling easier.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 17:51:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inactive-acl-in-asa/m-p/2309366#M311168</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-10T17:51:09Z</dc:date>
    </item>
    <item>
      <title>Inactive ACL in ASA</title>
      <link>https://community.cisco.com/t5/network-security/inactive-acl-in-asa/m-p/2309367#M311169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Many thanks Jonui&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 02:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inactive-acl-in-asa/m-p/2309367#M311169</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-10-11T02:56:29Z</dc:date>
    </item>
  </channel>
</rss>

