[c-nsp] Applying ACL

Roland Dobbins rdobbins at cisco.com
Wed May 30 14:19:47 EDT 2007


On May 30, 2007, at 11:07 AM, Leonardo Souza wrote:

> I'd like to know if it's secure update them doing:

A lot of folks leapfrog the numbers - so, for example, they've access- 
list 101 applied, and access-list 102 as a copy of access-list 101.   
They push an update to access-list 102, then alter the interface  
statements to apply 102.  When it's time for the next update, they do  
the same thing, but with 101.

The details of how ACLs are provisioned and instantiated vary from  
platform to platform, linecard to linecard.

------------------------------------------------------------------------
Roland Dobbins <rdobbins at cisco.com> // 408.527.6376 voice

You may not be interested in strategy, but strategy is interested in  
you.

                       -- Leon Trotsky



More information about the cisco-nsp mailing list