Overlapping ACL rules (2024)

Cisco ASA and Nexus devices evaluate rules in order, from top to bottom. Overlapping rules occur when some or all of the traffic that would have been processed by one rule has already been processed by a previous rule. When you view ACL rules for a Cisco ASA or Nexus device, SolarWinds NCM displays a warning icon Overlapping ACL rules (1) to identify overlapping rules.

Finding and eliminating overlapping rules reduces the size of the rule set, making it easier to manage, and also helps you ensure that the rules achieve the intended results.

NCM detects four types of overlapping rules on Cisco ASAand Nexus devices:

  • Fully shadowed
  • Partially shadowed
  • Fully redundant
  • Partially redundant

When detecting overlapping rules, NCM supports both contiguous and discontiguous masks.

Fully shadowed rules

A fully shadowed rule is detected when:

  • The criteria for one rule matches all of the traffic covered by a second rule.
  • The two rules apply different actions.

The second rule is fully shadowed by the first. The rules conflict, but the shadowed rule is never applied to any traffic because it comes later in the access list. For example:

Overlapping ACL rules (2)

Partially shadowed rules

A partially shadowed rule is detected when:

  • The criteria for one rule matches some of the traffic covered by a second rule.
  • The two rules apply different actions.

The second rule is partially shadowed by the first. It is applied to only some of the intended traffic. For example:

Overlapping ACL rules (3)

In some cases, a partially shadowed rule might be intentional. For example, you might want to permit traffic from specific IP addresses, but deny all others.

Fully redundant rules

A fully redundant rule is detected when:

  • The criteria for one rule matches all of the traffic covered by a second rule.
  • The two rules apply the same action.

The second rule is fully redundant because of the first. It is never applied to any traffic. For example:

Overlapping ACL rules (4)

Partially redundant rules

A partially redundant rule is detected when:

  • The criteria for one rule matches some of the traffic covered by a second rule.
  • The two rules apply the same action.

The second rule is partially redundant because of the first. It is applied to only some of the intended traffic. For example:

Overlapping ACL rules (5)

Overlapping ACL rules (2024)
Top Articles
Atlantic Tropical Weather Discussion
Soap2Day That 70S Show
417-990-0201
Splunk Stats Count By Hour
Garrison Blacksmith Bench
Pieology Nutrition Calculator Mobile
Top Financial Advisors in the U.S.
P2P4U Net Soccer
According To The Wall Street Journal Weegy
Which aspects are important in sales |#1 Prospection
OnTrigger Enter, Exit ...
Premier Boating Center Conroe
Maxpreps Field Hockey
Little Rock Arkansas Craigslist
Seattle Rpz
Lesson 8 Skills Practice Solve Two-Step Inequalities Answer Key
Po Box 35691 Canton Oh
The Ultimate Style Guide To Casual Dress Code For Women
Dirt Removal in Burnet, TX ~ Instant Upfront Pricing
Graphic Look Inside Jeffrey Dahmer
Atdhe Net
Aliciabibs
Bidevv Evansville In Online Liquid
Sandals Travel Agent Login
Chamberlain College of Nursing | Tuition & Acceptance Rates 2024
Meta Carevr
Cosas Aesthetic Para Decorar Tu Cuarto Para Imprimir
Weather October 15
Movies - EPIC Theatres
Weather Underground Durham
Mchoul Funeral Home Of Fishkill Inc. Services
Shiftwizard Login Johnston
Skroch Funeral Home
Federal Student Aid
AsROck Q1900B ITX und Ramverträglichkeit
Ewwwww Gif
Metra Schedule Ravinia To Chicago
Scottsboro Daily Sentinel Obituaries
Dr Adj Redist Cadv Prin Amex Charge
Trap Candy Strain Leafly
Final Jeopardy July 25 2023
Noaa Marine Weather Forecast By Zone
Oppenheimer Showtimes Near B&B Theatres Liberty Cinema 12
Hazel Moore Boobpedia
Sallisaw Bin Store
Shell Gas Stations Prices
Big Reactors Best Coolant
Youravon Com Mi Cuenta
This Doctor Was Vilified After Contracting Ebola. Now He Sees History Repeating Itself With Coronavirus
Every Type of Sentinel in the Marvel Universe
Dmv Kiosk Bakersfield
Latest Posts
Article information

Author: Gov. Deandrea McKenzie

Last Updated:

Views: 5818

Rating: 4.6 / 5 (46 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Gov. Deandrea McKenzie

Birthday: 2001-01-17

Address: Suite 769 2454 Marsha Coves, Debbieton, MS 95002

Phone: +813077629322

Job: Real-Estate Executive

Hobby: Archery, Metal detecting, Kitesurfing, Genealogy, Kitesurfing, Calligraphy, Roller skating

Introduction: My name is Gov. Deandrea McKenzie, I am a spotless, clean, glamorous, sparkling, adventurous, nice, brainy person who loves writing and wants to share my knowledge and understanding with you.