<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Line numder in ACL in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213274#M351098</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to add a single ACL rule (usually called ACE = Access Rule Entry) to an existing ACL then that will work just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You say you want to add an ACE to the &lt;STRONG&gt;line 16&lt;/STRONG&gt; of an existing ACL. This is no problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say you want to add this ACE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list INSIDE-IN permit ip host 10.10.10.10 host 20.20.20.20&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you instead wanted to add this to the &lt;STRONG&gt;line 16&lt;/STRONG&gt; of the ACL INSIDE-IN then you would enter it like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list INSIDE-IN &lt;SPAN style="color: #ff0000;"&gt;line 16&lt;/SPAN&gt; permit ip host 10.10.10.10 host 20.20.20.20&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This WONT remove the old &lt;STRONG&gt;line 16&lt;/STRONG&gt; rule. It will simply move that rule to &lt;STRONG&gt;line 17&lt;/STRONG&gt;. The same is naturally done for every rule after this new created rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Apr 2013 17:53:10 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-04-24T17:53:10Z</dc:date>
    <item>
      <title>Line numder in ACL</title>
      <link>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213273#M351097</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to add new ACL to ASA by command line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For interface say x&amp;nbsp; there are 50 lines of ACL.&lt;/P&gt;&lt;P&gt;if i make new acl and do not put any line number where it will show up ?&lt;/P&gt;&lt;P&gt;At bottom of all ACL?Will it work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want this ACL after line number 15 but there is already another ACL with line&amp;nbsp; number 16.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So need to know how can i add this ACL to existing ACL list to make it work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213273#M351097</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T01:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Line numder in ACL</title>
      <link>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213274#M351098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to add a single ACL rule (usually called ACE = Access Rule Entry) to an existing ACL then that will work just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You say you want to add an ACE to the &lt;STRONG&gt;line 16&lt;/STRONG&gt; of an existing ACL. This is no problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say you want to add this ACE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list INSIDE-IN permit ip host 10.10.10.10 host 20.20.20.20&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you instead wanted to add this to the &lt;STRONG&gt;line 16&lt;/STRONG&gt; of the ACL INSIDE-IN then you would enter it like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list INSIDE-IN &lt;SPAN style="color: #ff0000;"&gt;line 16&lt;/SPAN&gt; permit ip host 10.10.10.10 host 20.20.20.20&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This WONT remove the old &lt;STRONG&gt;line 16&lt;/STRONG&gt; rule. It will simply move that rule to &lt;STRONG&gt;line 17&lt;/STRONG&gt;. The same is naturally done for every rule after this new created rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 17:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213274#M351098</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-24T17:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Line numder in ACL</title>
      <link>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213275#M351099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you add an ACE to an ACL without any line number then it will simply be added to the bottom of the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wether it will work will depend if any ACE before it would deny the connection we are trying to allow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 17:55:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213275#M351099</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-24T17:55:14Z</dc:date>
    </item>
    <item>
      <title>Line numder in ACL</title>
      <link>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213276#M351101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So on line number 16 i want to add another subnet with new ACL.&lt;/P&gt;&lt;P&gt;So i can add using CLI&amp;nbsp; by using &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list INSIDE-IN line 15 permit ip host 10.10.10.10 host 20.20.20.20.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Then the new ACL with new&amp;nbsp; IP allowed&amp;nbsp; will show up in line number 16?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;MAhesh&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 18:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213276#M351101</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-24T18:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Line numder in ACL</title>
      <link>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213277#M351102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to add a new ACE to the ACL to line 16 then you will insert it in line 16.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This WONT remove the previous line 16 rule. It will move that rule one line further which would mean line 17.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take this example from my ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created the following ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA(config)# sh access-list EXAMPLE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE; 21 elements; name hash: 0xdf5404f2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 1 extended permit ip host 10.0.0.100 any (hitcnt=0) 0x80cf5155&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 2 extended permit ip host 10.0.0.101 any (hitcnt=0) 0x17dfe659&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 3 extended permit ip host 10.0.0.102 any (hitcnt=0) 0x2946abad&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 4 extended permit ip host 10.0.0.103 any (hitcnt=0) 0x569a394a&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 5 extended permit ip host 10.0.0.104 any (hitcnt=0) 0x034dbc34&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 6 extended permit ip host 10.0.0.105 any (hitcnt=0) 0x4f8d468f&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 7 extended permit ip host 10.0.0.106 any (hitcnt=0) 0xb34cc256&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 8 extended permit ip host 10.0.0.107 any (hitcnt=0) 0x7d5fa818&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 9 extended permit ip host 10.0.0.108 any (hitcnt=0) 0x1a8d1358&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 10 extended permit ip host 10.0.0.109 any (hitcnt=0) 0x1244eab3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 11 extended permit ip host 10.0.0.110 any (hitcnt=0) 0x29aaf5ba&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 12 extended permit ip host 10.0.0.111 any (hitcnt=0) 0x44555dea&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 13 extended permit ip host 10.0.0.112 any (hitcnt=0) 0x5187082b&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 14 extended permit ip host 10.0.0.113 any (hitcnt=0) 0xd86254f1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 15 extended permit ip host 10.0.0.114 any (hitcnt=0) 0x52a4cecf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;&lt;STRONG&gt;access-list EXAMPLE line 16 extended permit ip host 10.0.0.115 any (hitcnt=0) 0xcabb431e&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 17 extended permit ip host 10.0.0.116 any (hitcnt=0) 0xe24f375a&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 18 extended permit ip host 10.0.0.117 any (hitcnt=0) 0x1f2484a3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 19 extended permit ip host 10.0.0.118 any (hitcnt=0) 0x8381ee37&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 20 extended permit ip host 10.0.0.119 any (hitcnt=0) 0xbd711724&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 21 extended permit ip host 10.0.0.120 any (hitcnt=0) 0x18deed92&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I want to add a new ACE to the line 16 of that ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I enter the following command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA(config)# access-list EXAMPLE &lt;SPAN style="color: #ff0000;"&gt;line 16&lt;/SPAN&gt; permit ip host 10.0.0.254 any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I check what the same ACL looks like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA(config)# sh access-list EXAMPLE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE; 22 elements; name hash: 0xdf5404f2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 1 extended permit ip host 10.0.0.100 any (hitcnt=0) 0x80cf5155&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 2 extended permit ip host 10.0.0.101 any (hitcnt=0) 0x17dfe659&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 3 extended permit ip host 10.0.0.102 any (hitcnt=0) 0x2946abad&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 4 extended permit ip host 10.0.0.103 any (hitcnt=0) 0x569a394a&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 5 extended permit ip host 10.0.0.104 any (hitcnt=0) 0x034dbc34&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 6 extended permit ip host 10.0.0.105 any (hitcnt=0) 0x4f8d468f&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 7 extended permit ip host 10.0.0.106 any (hitcnt=0) 0xb34cc256&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 8 extended permit ip host 10.0.0.107 any (hitcnt=0) 0x7d5fa818&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 9 extended permit ip host 10.0.0.108 any (hitcnt=0) 0x1a8d1358&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 10 extended permit ip host 10.0.0.109 any (hitcnt=0) 0x1244eab3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 11 extended permit ip host 10.0.0.110 any (hitcnt=0) 0x29aaf5ba&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 12 extended permit ip host 10.0.0.111 any (hitcnt=0) 0x44555dea&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 13 extended permit ip host 10.0.0.112 any (hitcnt=0) 0x5187082b&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 14 extended permit ip host 10.0.0.113 any (hitcnt=0) 0xd86254f1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 15 extended permit ip host 10.0.0.114 any (hitcnt=0) 0x52a4cecf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;access-list EXAMPLE line 16 extended permit ip host 10.0.0.254 any (hitcnt=0) 0x4886b292&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;&lt;STRONG&gt;access-list EXAMPLE line 17 extended permit ip host 10.0.0.115 any (hitcnt=0) 0xcabb431e&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 18 extended permit ip host 10.0.0.116 any (hitcnt=0) 0xe24f375a&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 19 extended permit ip host 10.0.0.117 any (hitcnt=0) 0x1f2484a3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 20 extended permit ip host 10.0.0.118 any (hitcnt=0) 0x8381ee37&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 21 extended permit ip host 10.0.0.119 any (hitcnt=0) 0xbd711724&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list EXAMPLE line 22 extended permit ip host 10.0.0.120 any (hitcnt=0) 0x18deed92&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice that the same ACL now&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is 22 lines instead of 21 lines since we inserted the new rule. So NO rules were removed.&lt;/LI&gt;&lt;LI&gt;Has the new rule added correctly in the line 16&lt;/LI&gt;&lt;LI&gt;The old line 16 rule was moved 1 line down to line 17&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 18:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213277#M351102</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-24T18:17:38Z</dc:date>
    </item>
    <item>
      <title>Line numder in ACL</title>
      <link>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213278#M351103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Jouni.&lt;/P&gt;&lt;P&gt;You got 5 out of 5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 18:24:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/line-numder-in-acl/m-p/2213278#M351103</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-24T18:24:33Z</dc:date>
    </item>
  </channel>
</rss>

