[c-nsp] Modifying ACLs on production router
Grzegorz Janoszka
Grzegorz at Janoszka.pl
Sun Oct 5 14:58:41 EDT 2008
Matlock, Kenneth L wrote:
> So from then on, I've always removed the ACL from the interface, removed the ACL, rebuilt it, and re-applied it to the interface. If you have the lines copied into a clipboard, you can paste the stuff in fairly quickly, and not really allow much 'bad' traffic in.
The simplest thing is to prepare a file containing "no acl XXX" and then
redefinition of the acl, put it of tftp server and load it using:
copy tftp://I.P.I.P/acl running-config
You do not need any extra tricks to do it, like temporary acl's and do on.
--
Grzegorz Janoszka
More information about the cisco-nsp
mailing list