Dynamic ACLs on any IOS release?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-14-2010 08:56 AM - edited 03-04-2019 10:07 AM
One of our vendors uses DNS host names to advertise the IP addresses for certain servers. the IP addresses for those server seem to be changing quite frequently.
Is there any way in any router or ASA release to dynamically adjust ACLs to compensate for that? I tried to use a DNS host name in a simple ACL and the name is resolved and the IP address used instead of the host name.
I assume this is not possible, but I figured I'd ask the esperts here.
thanks
Joerg
- Labels:
-
Other Routing
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-14-2010 12:39 PM
Hi,
The ACL can only reference to IP not to name.
If the server's address change they change within a range correct?
So you can configure the ACL to point to the range instead than the single IP.
i.e.
If the server 1.1.1.1 switches IP between 1.1.1.1-1.1.1.14
You can have your ACL point to 1.1.1.0/28
Just a thought.
Federico.
