Great Circle Associates Firewalls
(July 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Changing a (cisco) firewall setup.
From: "Jim Carroll" <jcarroll @ wellspring . us . dg . com>
Organization: Data General (Canada) Inc.
Date: Wed, 19 Jul 1995 14:40:38 -0500
To: firewalls @ greatcircle . com
Comments: Authenticated sender is <jcarroll @ wellspring . us . dg . com>
Priority: normal
Reply-to: jcarroll @ wellspring . us . dg . com

Rumour has it that on 19 Jul 95 at 9:41, Greg Nenych said:

> I think there's some confusion here about this point.  Let's say that
> you have a setup something like
> 
> 	access-list 101 whatever...
> 	interface ethernet 0
> 	ip access-group 101
> 
> and you want to change the access list in a secure manner.  To do this,
> create a new access list, verify that you typed it in correctly, and then
> apply it to the interface.
> 
> 	access-list 102 whatever...
> 	interface ethernet 0
> 	ip access-group 102

Understood.  No confusion here.

But that presumes we are not fallible.  If you have the scenario:

     access-list 102 ...
     access-list 102 ...
     access-list 102 ...
     access-list 102 ...
  (dang, wrong order!)
     no access-list 102 ...
     access-list 102 ...
     access-list 102 ...
     access-list 102 ...
     access-list 102 ...
     access-list 102 ...
     access-list 102 ...
  (dang, a typo!)
     no access-list 102 ...
     access-list 102 ...
     access-list 102 ...
     access-list 102 ...
     access-list 102 ...
     access-list 102 ...
  (dang, wrong order again!)

  [horribly graphic details of seppuku deleted]

Aside from the obvious kludges which might incorporate 
cu/tip/expect/cut&paste, are there any clever solutions to this 
problem?  (the Cisco config, not the graphic rendering of ritual 
suicide)

--
Jim Carroll - jcarroll @
 wellspring .
 us .
 dg .
 com
... the usual disclaimers ...
## The more I learn, the less I know.             ##
## Eventually I'll know everything about nothing. ##


Follow-Ups:
Indexed By Date Previous: Re: UDP with firewalls...
From: sten @ ergon . CH (Sten Gunterberg)
Next: Re: UDP with firewalls...
From: long-morrow @ CS . YALE . EDU
Indexed By Thread Previous: E-mail virus scanning
From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Next: Re: Changing a (cisco) firewall setup.
From: Adam Safier <asafier @ explorer . csc . com>

Google
 
Search Internet Search www.greatcircle.com