[f-nsp] FastIron ACL sequencing

Randy McAnally rsm at fast-serv.com
Mon Sep 12 11:58:47 EDT 2011


I already do this.  But with implicit deny there is a brief interruption of traffic.  Is there a way to avoid this?

~Randy

On Mon, 12 Sep 2011 11:45:59 -0400, Scott T. Cameron wrote
> Remove the ACL, make your changes, re-apply the ACL.
> 
> On Mon, Sep 12, 2011 at 11:42 AM, Randy McAnally <rsm at fast-serv.com> wrote:
> Looks like my FESX doesn't support ACL sequencing (like a stone-age Cisco) so
> I'm open for ideas on how to accomplish basic adds to a deny list and moving
> 'allow ip any any' to the end without interrupting traffic.
> 
> ~Randy
> 
> _______________________________________________
> foundry-nsp mailing list
> foundry-nsp at puck.nether.net
> http://puck.nether.net/mailman/listinfo/foundry-nsp
>

~Randy
 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://puck.nether.net/pipermail/foundry-nsp/attachments/20110912/e91a5641/attachment.html>


More information about the foundry-nsp mailing list