cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2178
Views
0
Helpful
1
Replies

PIX/ASA ACL: Inactive vs. deleting acl

onslaught99
Level 1
Level 1

Hello,

We are in the middle of auditing our acls on our PIX/ASA firewalls and had a question. What is the Cisco security best practice, delete acl's that are determined not in use or delete them? A few of our engineers have been marking unused acl's on the firewalls as inactive after the acl command. I understand that this makes that enty not usable, but does that still affect the firewall processing the acl's when it receives traffic? And we are also wanting to clean up our firewalls so that when we do a show run, we are not looking at pages and pages of config. There are a lot of ACE's that are inactive. Would it be better to just delete them? Any help would be greatly appreciative.

Thanks

1 Reply 1

varrao
Level 10
Level 10

Hi,

Obviously, the configuration that you don't need should always be deleted, I remember a case wherein the customer had network down situation, but it was found that by mistake someone had unchecked the acl in the ASDM and made it inactive, since they had a lot of inactive acl's in ASDM they did not come to know that the acl was made inactive.

So I woudl suggest that always get rid of redundant ACL, moreover if someone make the inactive acl active, would be difficult for you to identify.

Hope this helps.

Thanks,

Varun

Thanks,
Varun Rao
Review Cisco Networking products for a $25 gift card