cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
361
Views
1
Helpful
2
Replies

Isr 1100 reflexive ACL

fanciho2
Level 1
Level 1

Hi, is there a version of ios-xe supporting reflexive access list? I try to migrate a config fotm c897va to a c1117 and the reflexive or evaluate keywords are unknown. (17.12.4 is,on thd device) Or has the syntax changed?

Is there a script to convert such ACLs to use the ios firewall feature, or has someone tips how to transfer functionality?

2 Replies 2

you need to use Zone firewall instead 
use class-map inspect the ACL of traffic 
policy-map inspect the class-map above and action will be inspect
zone pair between two interface 

this same as reflexive ACL I think

MHM

@fanciho2 

 The limitation is related to ISR1100 not with the IOS-XE specifically