
13-19
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 13 Identifying Traffic with Access Lists
Access List Group Optimization
After optimization:
access-list test extended permit udp 10.1.1.0 255.255.255.0 any [rule x]
•
Adjacency—If rule x is adjacent to rule y, rule y is merged up with rule x.
Before optimization:
access-list test extended permit ip 10.1.1.0 255.255.255.128 any [rule x]
access-list test extended permit ip 10.1.1.128 255.255.255.128 any [rule y]
After optimization:
access-list test extended permit ip 10.1.1.0 255.255.255.0 any [rule x]
•
Overlap—If rule x overlaps rule y, rule y is merged up with rule x.
Before optimization:
access-list test extended permit tcp any any range 50 100 [rule x]
access-list test extended permit tcp any any range 60 120 [rule y]
After optimization:
access-list test extended permit tcp any any range 50 120 rule x]
Note
Two redundant/overlapping rules cannot be merged if there exists a conflicting rule in the access list
located in between the two rules.
•
Permit/Deny—If rule x overlaps with rule y and rule z and rule y has an opposite permission/action,
rule x cannot be merged with rule z even though both rules have the same permission/action.
Before optimization:
access-list test extended permit tcp any any range 50 100 [rule x]
access-list test extended deny tcp any any range 80 130 [rule y]
access-list test extended permit tcp any any range 60 120 [rule z]
After optimization:
access-list test extended permit tcp any any range 50 100 [rule x]
access-list test extended deny tcp any any range 80 130 [rule y]
access-list test extended permit tcp any any range 60 120 [rule z]
•
Logging (default, disable keywords)—If rule x with a “log default” keyword overlaps with rule y
with a “log disable” keyword, rule x can be merged with rule y only if both rules have a “permit”
action.
Before optimization:
access-list test extended permit tcp any any range 50 100 log default [rule x]
access-list test extended permit tcp any any range 80 130 log disable [rule y]
After optimization:
access-list test extended permit tcp any any range 50 130 log default [rule x]
Before optimization:
access-list test extended deny tcp any any range 50 100 log default [rule x]
access-list test extended deny tcp any any range 80 130 log disable [rule y]
After optimization:
access-list test extended deny tcp any any range 50 100 log default [rule x]
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......