[c-nsp] Modifying ACLs on production router

Grzegorz Janoszka Grzegorz at Janoszka.pl
Sun Oct 5 14:58:41 EDT 2008


Matlock, Kenneth L wrote:
> So from then on, I've always removed the ACL from the interface, removed the ACL, rebuilt it, and re-applied it to the interface. If you have the lines copied into a clipboard, you can paste the stuff in fairly quickly, and not really allow much 'bad' traffic in.

The simplest thing is to prepare a file containing "no acl XXX" and then 
redefinition of the acl, put it of tftp server and load it using:
copy tftp://I.P.I.P/acl running-config

You do not need any extra tricks to do it, like temporary acl's and do on.

-- 
Grzegorz Janoszka


More information about the cisco-nsp mailing list