Huawei ACL resequence

If an additional entry is added or deleted in an ACL (access control list), then the sequence numbers are no longer correct. Instead of deleting the ACL and adding it again, there is the option of resequencing or renumbering which is shown here with an example.

When creating an ACL without specifying the rule ID, the sequence number (called rule by Huawei) is created in increments of 5.

To check this we create a standard ACL with two entries without specifying the rule ID:

[HUAWEI]acl 2000
[HUAWEI-acl-basic-2000]rule deny source 1.1.1.1 0
[HUAWEI-acl-basic-2000]rule deny source 3.3.3.3 0
[HUAWEI-acl-basic-2000]dis acl 2000
Basic ACL 2000, 2 rules
Acl's step is 5
rule 5 deny source 1.1.1.1 0
rule 10 deny source 3.3.3.3 0

We can see that the rule ID is 5 by default. If you want to create another entry between the two entries, this can be done with specifying the rule ID (6 in this example):

[HUAWEI-acl-basic-2000]rule 6 deny source 2.2.2.2 0
[HUAWEI-acl-basic-2000]dis acl 2000
Basic ACL 2000, 3 rules
Acl's step is 5
rule 5 deny source 1.1.1.1 0
rule 6 deny source 2.2.2.2 0
rule 10 deny source 3.3.3.3 0

This can be done until there are no free rule IDs left. And also from a cosmetic point of view it may be that this wants to be reset to the standard IDs. This resequence can be done with the undo step command:

[HUAWEI-acl-basic-2000]undo step
[HUAWEI-acl-basic-2000]dis acl 2000
Basic ACL 2000, 3 rules
Acl's step is 5
rule 5 deny source 1.1.1.1 0
rule 10 deny source 2.2.2.2 0
rule 15 deny source 3.3.3.3 0

If you want to increase the renumbering to 10 instead, this can also easily be done with the step command:

[HUAWEI-acl-basic-2000]rule 11 deny source 4.4.4.4 0
[HUAWEI-acl-basic-2000]dis acl 2000
Basic ACL 2000, 4 rules
Acl's step is 5
rule 5 deny source 1.1.1.1 0
rule 10 deny source 2.2.2.2 0
rule 11 deny source 4.4.4.4 0
rule 15 deny source 3.3.3.3 0

[HUAWEI-acl-basic-2000]step 10
[HUAWEI-acl-basic-2000]dis acl 2000
Basic ACL 2000, 4 rules
Acl's step is 10
rule 10 deny source 1.1.1.1 0
rule 20 deny source 2.2.2.2 0
rule 30 deny source 4.4.4.4 0
rule 40 deny source 3.3.3.3 0

The same process also applies to an advanced or named ACL.

Loading comment... The comment will be refreshed after 00:00.
Write comments...
You are a guest ( Sign Up ? )
or post as a guest

Newsletter