<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOS ACL to FWSM format conversion tool ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-acl-to-fwsm-format-conversion-tool/m-p/1206394#M859533</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firstly with sincere apologies to all Perl programmers :-), i have knocked up a quick script that will convert IOS acl to FWSM/Pix/ASA format eg. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Input = &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp 192.168.10.0 0.0.0.255 172.16.5.0 0.0.0.7 eq 23&lt;/P&gt;&lt;P&gt;access-list 101 permit udp 192.168.20.0 0.0.0.31 eq 23 172.16.5.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 101 permit ip host 192.168.10.1 172.31.12.0 0.0.7.255&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 192.168.17.128 0.0.0.127 172.16.10.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 172.16.5.0 0.0.0.31 host 172.16.5.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Output = &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp 192.168.10.0 255.255.255.0 172.16.5.0 255.255.255.248 eq 23 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit udp 192.168.20.0 255.255.255.224 eq 23 172.16.5.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip host 192.168.10.1 172.31.12.0 255.255.248.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip 192.168.17.128 255.255.255.128 172.16.10.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip 172.16.5.0 255.255.255.224 host 172.16.5.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It only works with IOS acl's of format &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list &lt;ACL number=""&gt; permit ....&lt;/ACL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i suppose it could be modified to also include extended acl's. It's a very quick and dirty script and i haven't exactly tested it extensively but if you have huge acl's it may be worth a try. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully you are familiar with Perl. If not you can get a copy for windows from Activestate (www.activestate.com). Linux/Unix should already have it installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Script attached. Obviously this comes with no guarantees so use with discretion !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** Edit - sorry should explain. Script will read in a file containing an IOS access-list and will output to the screen the new FWSM access-list. **&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Jun 2009 10:59:40 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2009-06-04T10:59:40Z</dc:date>
    <item>
      <title>IOS ACL to FWSM format conversion tool ?</title>
      <link>https://community.cisco.com/t5/network-security/ios-acl-to-fwsm-format-conversion-tool/m-p/1206392#M859531</link>
      <description>&lt;P&gt;Is there a tool to convert IOS ACL to FWSM format ?&lt;/P&gt;&lt;P&gt;i.e. conversion of wildcard masks to appropriate subnet mask&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-acl-to-fwsm-format-conversion-tool/m-p/1206392#M859531</guid>
      <dc:creator>p.brand</dc:creator>
      <dc:date>2019-03-11T15:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: IOS ACL to FWSM format conversion tool ?</title>
      <link>https://community.cisco.com/t5/network-security/ios-acl-to-fwsm-format-conversion-tool/m-p/1206393#M859532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have not been able to find an app, but what I do is use a text editor (my favorite is UltraEdit) and do a search and replace. Search for 255.255.255.248 and replace with 0.0.0.7. Clunky, but it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 14:58:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-acl-to-fwsm-format-conversion-tool/m-p/1206393#M859532</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-06-03T14:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: IOS ACL to FWSM format conversion tool ?</title>
      <link>https://community.cisco.com/t5/network-security/ios-acl-to-fwsm-format-conversion-tool/m-p/1206394#M859533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firstly with sincere apologies to all Perl programmers :-), i have knocked up a quick script that will convert IOS acl to FWSM/Pix/ASA format eg. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Input = &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp 192.168.10.0 0.0.0.255 172.16.5.0 0.0.0.7 eq 23&lt;/P&gt;&lt;P&gt;access-list 101 permit udp 192.168.20.0 0.0.0.31 eq 23 172.16.5.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 101 permit ip host 192.168.10.1 172.31.12.0 0.0.7.255&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 192.168.17.128 0.0.0.127 172.16.10.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 172.16.5.0 0.0.0.31 host 172.16.5.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Output = &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp 192.168.10.0 255.255.255.0 172.16.5.0 255.255.255.248 eq 23 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit udp 192.168.20.0 255.255.255.224 eq 23 172.16.5.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip host 192.168.10.1 172.31.12.0 255.255.248.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip 192.168.17.128 255.255.255.128 172.16.10.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip 172.16.5.0 255.255.255.224 host 172.16.5.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It only works with IOS acl's of format &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list &lt;ACL number=""&gt; permit ....&lt;/ACL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i suppose it could be modified to also include extended acl's. It's a very quick and dirty script and i haven't exactly tested it extensively but if you have huge acl's it may be worth a try. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully you are familiar with Perl. If not you can get a copy for windows from Activestate (www.activestate.com). Linux/Unix should already have it installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Script attached. Obviously this comes with no guarantees so use with discretion !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** Edit - sorry should explain. Script will read in a file containing an IOS access-list and will output to the screen the new FWSM access-list. **&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 10:59:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-acl-to-fwsm-format-conversion-tool/m-p/1206394#M859533</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-06-04T10:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: IOS ACL to FWSM format conversion tool ?</title>
      <link>https://community.cisco.com/t5/network-security/ios-acl-to-fwsm-format-conversion-tool/m-p/1206395#M859535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apologies, here is the attachement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 11:02:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-acl-to-fwsm-format-conversion-tool/m-p/1206395#M859535</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-06-04T11:02:06Z</dc:date>
    </item>
  </channel>
</rss>

