<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access List Analyser/Auditor in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/1942806#M969022</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check out this Page, there are some Analyzing Software listed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.filebuzz.com/findsoftware/Access_List_Analyzer/1.html" rel="nofollow"&gt;http://www.filebuzz.com/findsoftware/Access_List_Analyzer/1.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or u can try Notepad++ there you can with a compare Plugin wonderful compare things.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 May 2012 10:05:25 GMT</pubDate>
    <dc:creator>steffen.buehnemann</dc:creator>
    <dc:date>2012-05-31T10:05:25Z</dc:date>
    <item>
      <title>Access List Analyser/Auditor</title>
      <link>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/1942804#M969018</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have recently started in a new comany as its senior network engineer and have inherited a mess of Access Lists on Cat 6513s / ASAs and PIXs. Some of the ACLs on the 6513 have over 1000+ lines plus each and there are loads of them, and I know for a fact that they contain duplicate entries or entries that are negated by a ip any any or similar in the middle of the ACL. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; So I was wondering if anybody knows of a useful available tool that will take an imported ACL by a text file for instance, analyse that ACL and highlight any duplicate or negated ACL Entries. This would save me a headache from sifting through each ACL line by line. one ACL for example has 3000+ lines.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:39:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/1942804#M969018</guid>
      <dc:creator>williamsryan</dc:creator>
      <dc:date>2020-02-21T12:39:18Z</dc:date>
    </item>
    <item>
      <title>Access List Analyser/Auditor</title>
      <link>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/1942805#M969020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;most useful available tool is 2 notepads on 2 different monitors&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dont forget to rate post&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 10:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/1942805#M969020</guid>
      <dc:creator>Tagir Temirgaliyev</dc:creator>
      <dc:date>2012-05-29T10:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Access List Analyser/Auditor</title>
      <link>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/1942806#M969022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check out this Page, there are some Analyzing Software listed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.filebuzz.com/findsoftware/Access_List_Analyzer/1.html" rel="nofollow"&gt;http://www.filebuzz.com/findsoftware/Access_List_Analyzer/1.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or u can try Notepad++ there you can with a compare Plugin wonderful compare things.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2012 10:05:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/1942806#M969022</guid>
      <dc:creator>steffen.buehnemann</dc:creator>
      <dc:date>2012-05-31T10:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Access List Analyser/Auditor</title>
      <link>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/3216471#M969023</link>
      <description>&lt;P&gt;I feel your pain.&amp;nbsp; You might try the GUI (ASDM) to see if that helps parse through the hundreds of lines of rules.&amp;nbsp; It will take a while regardless, but this method might speed up the process as you can click on objects to gather info as opposed to the CLI method.&amp;nbsp; I'm a CLI guy, but sometimes the GUI is faster.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 17:16:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/3216471#M969023</guid>
      <dc:creator>afunk</dc:creator>
      <dc:date>2017-11-14T17:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Access List Analyser/Auditor</title>
      <link>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/3374265#M969026</link>
      <description>&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=G-Pk4mt-3eg" target="_blank"&gt;https://www.youtube.com/watch?v=G-Pk4mt-3eg&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It's my program. Beta version.&lt;/P&gt;
&lt;P&gt;So far, only in Russian.&lt;BR /&gt;If it is in demand, I will translate it into English in the future.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 05:39:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/3374265#M969026</guid>
      <dc:creator>GSA</dc:creator>
      <dc:date>2018-04-27T05:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Access List Analyser/Auditor</title>
      <link>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/3374523#M969027</link>
      <description>&lt;P&gt;Cisco Security Manager and Tufin come to mind.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/security-manager/datasheet-C78-737182.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/security-manager/datasheet-C78-737182.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.tufin.com/solutions/firewall-optimization" target="_blank"&gt;https://www.tufin.com/solutions/firewall-optimization&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SolarWinds recently discontinued Firewall Security Manager (former Athena Firepac product) which also did a great job at this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 14:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/3374523#M969027</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-04-27T14:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Access List Analyser/Auditor</title>
      <link>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/3898752#M969029</link>
      <description>&lt;P&gt;I recently released "Network Mom ACL Analyzer" in the MacOS 10.14 App Store.&lt;/P&gt;&lt;P&gt;It supports analysis of IPv4 security ACLs for the following OS flavors:&lt;/P&gt;&lt;P&gt;1) IOS (without object-groups)&lt;/P&gt;&lt;P&gt;2) IOS-XR (with object-groups)&lt;/P&gt;&lt;P&gt;3) NX-OS (with object-groups)&lt;/P&gt;&lt;P&gt;4) ASA (with network object-groups, but not service object-groups)&lt;/P&gt;&lt;P&gt;It has the following features:&lt;/P&gt;&lt;P&gt;1) ACL syntax check&lt;/P&gt;&lt;P&gt;2) Reports wildcard bits that do not match a proper subnet as an error&lt;/P&gt;&lt;P&gt;3) Warns about CIDRs that are not on a bit boundary&lt;/P&gt;&lt;P&gt;4) Analyzes a specific TCP/UDP socket against an ACL to find lines that match&lt;/P&gt;&lt;P&gt;5) Duplicate ACL detection! &amp;nbsp;Finds lines in the ACL which are a strict superset of later lines.&lt;/P&gt;&lt;P&gt;It can perform a permit/deny analysis of a specific socket against a 50,000-line ACL in under 20 seconds (reasonably sized ACLs are analyzed "instantly").&lt;/P&gt;&lt;P&gt;Duplicate ACL detection takes 3 seconds (on a 2013 iMac) for a 2,000-line ACL. &amp;nbsp;As the number of lines doubles the processing time quadruples (it analyzed a 10,000-line ACL for duplicates in a couple of minutes).&lt;/P&gt;&lt;P&gt;For the security of your ACLs, the tool passed Apple app review and uses Apple's app sandbox and hardened runtime features. &amp;nbsp;The analyzer is not allowed to make or receive network connections. &amp;nbsp;It does not save ACL information between application runs. &amp;nbsp;It can only open files outside the sandbox that the user specifies. &amp;nbsp;Files are always opened read-only. &amp;nbsp;The tool is implemented in the Swift programming language.&lt;/P&gt;&lt;P&gt;Darrell&lt;/P&gt;&lt;P&gt;CCIE Emeritus #8302&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2019 00:31:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-analyser-auditor/m-p/3898752#M969029</guid>
      <dc:creator>daroot</dc:creator>
      <dc:date>2019-07-28T00:31:06Z</dc:date>
    </item>
  </channel>
</rss>

