<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Managing ACE line numbers manually in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/managing-ace-line-numbers-manually/m-p/2090684#M392545</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding in Cisco firewalls line numbers are a continuous value for example from 1 - 7. There is no situation where there is line 1 and line 7 only. Only situation where you need to use line number is when you want to add something in between the existing rules and not at the bottom of them rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Depending on how your ACL / rules are built you might end up entering every ACE on a certain line since you might have some manually configured deny statement in the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Cisco routers however there is possibility to do what you are talking about in your post. In the router extended ACLs its possibility to use the sequence number to make one rule of very high value and one very low value without having something in between them&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to my knowledge this is not possible in the PIX / FWSM / ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You simply need to check where you enter the new rule to keep the ACL in working order.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Heres a quote from the command reference (ASA 8.4) (same applies to FWSM)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;STRONG&gt;line line-num &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Optional) Specifies the line number at which to insert the ACE. If you do&lt;/P&gt;&lt;P&gt;not specify a line number, the ACE is added to the end of the access list.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The line number is not saved in the configuration; it only specifies where&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;to insert the ACE.&lt;/STRONG&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 19 Jan 2013 18:12:19 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-01-19T18:12:19Z</dc:date>
    <item>
      <title>Managing ACE line numbers manually</title>
      <link>https://community.cisco.com/t5/network-security/managing-ace-line-numbers-manually/m-p/2090683#M392542</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to manually control ACL ACE line numbers? I have FWSM 4.1(10). It appears that no matter whatever number you give for a new ACE, it is automatically added to the bottom in sequential number 5,6,7...(and not the number you give), unless it is replacing the existing ACE, which in that case pushes the original ACE to the next line number. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to keep an ACE at the last, with very high number (say 15000) and add new ACEs like 500, 501. Is it possible?&lt;/P&gt;&lt;P&gt;If it is not possible, what is the best way to make sure that a particular ACE is always at the bottom of an ACL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks much!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:49:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managing-ace-line-numbers-manually/m-p/2090683#M392542</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2019-03-12T00:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Managing ACE line numbers manually</title>
      <link>https://community.cisco.com/t5/network-security/managing-ace-line-numbers-manually/m-p/2090684#M392545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding in Cisco firewalls line numbers are a continuous value for example from 1 - 7. There is no situation where there is line 1 and line 7 only. Only situation where you need to use line number is when you want to add something in between the existing rules and not at the bottom of them rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Depending on how your ACL / rules are built you might end up entering every ACE on a certain line since you might have some manually configured deny statement in the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Cisco routers however there is possibility to do what you are talking about in your post. In the router extended ACLs its possibility to use the sequence number to make one rule of very high value and one very low value without having something in between them&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to my knowledge this is not possible in the PIX / FWSM / ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You simply need to check where you enter the new rule to keep the ACL in working order.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Heres a quote from the command reference (ASA 8.4) (same applies to FWSM)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;STRONG&gt;line line-num &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Optional) Specifies the line number at which to insert the ACE. If you do&lt;/P&gt;&lt;P&gt;not specify a line number, the ACE is added to the end of the access list.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The line number is not saved in the configuration; it only specifies where&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;to insert the ACE.&lt;/STRONG&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2013 18:12:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managing-ace-line-numbers-manually/m-p/2090684#M392545</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-19T18:12:19Z</dc:date>
    </item>
  </channel>
</rss>

