Re: [nsp] ACL optimizer..

From: kevin graham (kgraham@dotnetdotcom.org)
Date: Mon May 13 2002 - 18:26:44 EDT


On Mon, 13 May 2002, dre wrote:

> i also saw aclgen-2.02 in the freebsd ports collection.
> others use CIDRAdvisor that comes with the IRRToolSet.
> i'm sure there are other tools, but those three just
> came to mind.

Thanks for the pointers. The main thing I was looking for was something
that took the trouble of figuring out non-continuous masks (ie.
5.0.0.0 8.255.255.255 to compress 5/8 and 13/18), where mental
bittwiddling starts to hurt..

On Mon, 13 May 2002, Rubens Kuhl Jr. wrote:

> Keeping readability may be done by always keeping the source ACL to edit
> and using the modified only to deploy it on routers.
                                                                                
True. I'm still hoping that maybe, just maybe we'll get inclusive ACL's
(ie. being able to use 'evaluate' for something other than reflexives) one
day to centrally control 'stock' acl's w/o having to copy each time to
iface specific ones...

thanks.

..kg..



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:13:44 EDT