nanog mailing list archives

Re: (cisco, or any) acl *reducers* out there?


From: Randy Bush <randy () psg com>
Date: Thu, 19 Aug 2010 12:00:48 +0900

something which can take a couple of hundred basic and extended ACLs and tell you
 these <ten> don't work
 these <twenty> conflict
 the remaining <x> have a sequence and can reduce to this basic <x-y> set

maybe you could go the other direction.  as opposed to trying to digest
and correct cruft, generate the acls from something reasonable so that
they are canonic by construction.

randy


Current thread: