cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3082
Views
10
Helpful
4
Replies

Transfer Rules from One interface to Another - Cisco ASA

NeWGuy1109
Level 1
Level 1

I have an ASA with about 8 subinterfaces.. due to a recent requirement the rules in 2 subinterfaces are required to be transferred to a new subinterface..

 

for ex: interface A - 100 rules

Interfaces B - 50 rules 

New Interface C - 100+50 = 150 rules

 

What is the best way i can combine rules from A and B and move them over to C ? 

i read that via access-group command i can copy rules from one to another but isnt it 1 to 1 mapping only ? 

any other way to do this efficiently.

 

Thanks 

2 Accepted Solutions

Accepted Solutions

Hello @NeWGuy1109,

 

That is true, the access-group command is a 1-to-1 mapping and there is no such command to combine two different access-lists to one. Personally, I would recommend copying all the rules to a text editor such as notepad, combine them and paste with a new name. This way you can manage them all separately.

 

***Please mark all helpful responses***

Spooster IT Services Team

View solution in original post

@NeWGuy1109 

 

You are copying the "show access-list" output. You need to copy the "show runn access-list" command output that will get rid of these values.

Spooster IT Services Team

View solution in original post

4 Replies 4

Hello @NeWGuy1109,

 

That is true, the access-group command is a 1-to-1 mapping and there is no such command to combine two different access-lists to one. Personally, I would recommend copying all the rules to a text editor such as notepad, combine them and paste with a new name. This way you can manage them all separately.

 

***Please mark all helpful responses***

Spooster IT Services Team

Thanks for the reply..

 

the only issue with it is that while copying the access rules ..at the very end of each line i am getting these values

(hitcount=2???) 0x????

which are different for each line..any way i can remove these together ?

@NeWGuy1109 

 

You are copying the "show access-list" output. You need to copy the "show runn access-list" command output that will get rid of these values.

Spooster IT Services Team

Thanks a lot