01-31-2013 06:59 PM - edited 03-07-2019 11:26 AM
Hi
We got hunderds access-list lines on switch, I just wondering if there is a tool which I can use it to test if a added ACL line works, just like the packet-tracer command in ASA.
Thanks.
01-31-2013 08:02 PM
You could use the nmap utility on a Linux system. It is a port scanning utility. The issue though comes from your source IP in the acl. How would the 'tool' or 'app' mimic the source IP without doing a self inflicted DoS on your network? Best approach is to write a similar acl line from a test subnet and run your port scanner to test the acl line.
-Toby
Sent from Cisco Technical Support Android App
02-05-2013 06:47 PM
HI Toby
Thanks for your reply, but I think nmap isn't the best tool for me, the swtich is on remote site, I unable to use nmap for testing.
/Brad
02-05-2013 07:00 PM
Hi,
May be this will help you
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml
Hope it will help.
Best regards,
Abzal
08-04-2016 04:38 PM
Hello,
Try this tool!
https://supportforums.cisco.com/document/13067081/access-list-checker
Kind regards,
Jae
04-26-2018 10:22 PM
https://www.youtube.com/watch?v=G-Pk4mt-3eg
So far, only in Russian.
If it is in demand, I will translate it into English in the future.
05-15-2020 09:16 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide