<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.netcordia.com/community/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Drew&amp;#39;s Blog</title><link>http://www.netcordia.com/community/blogs/drews_blog/default.aspx</link><description>&lt;a href="http://connection.netcordia.com/blogs/drews_blog/rss.aspx"&gt;&lt;img src="http://connection.netcordia.com/img/rss40.png" alt="RSS Feed" /&gt;&lt;/a&gt;</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 SP2 (Build: 31113.47)</generator><item><title>NetMRI and Me: ACL's, Vlan Access-Maps, and what NOT to do.</title><link>http://www.netcordia.com/community/blogs/drews_blog/archive/2009/06/30/how-netmri-helped-me-acl-s-and-vlan-access-maps.aspx</link><pubDate>Tue, 30 Jun 2009 19:47:00 GMT</pubDate><guid isPermaLink="false">5d983763-db35-4d57-ab7d-8a0a48ffcea2:1500</guid><dc:creator>dpatten</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.netcordia.com/community/blogs/drews_blog/rsscomments.aspx?PostID=1500</wfw:commentRss><comments>http://www.netcordia.com/community/blogs/drews_blog/archive/2009/06/30/how-netmri-helped-me-acl-s-and-vlan-access-maps.aspx#comments</comments><description>&lt;p&gt;Greetings from Annapolis, my name is Drew and I am the System Administrator here at Netcordia.&amp;nbsp; I am relatively new to blogging, actually this blog entry is my first.&amp;nbsp; So to start it off I thought I would share an experience I had here at work while working with ACL&amp;#39;s, vlan access-maps and our in-house NetMRI. &lt;/p&gt;&lt;p&gt;I was updating an ACL on our core router and in the process of doing so deleted what I thought was an old outdated and un-used ACL.&amp;nbsp; Minutes later I had two developers in my office and multiple emails from our development team stating they could not reach their development machines, all of which were located on a separate development vlan.&amp;nbsp; Great! I just deleted the ACL that allowed traffic to and from that development vlan, hopefully I made a copy of it.&amp;nbsp; Doh!&amp;nbsp; No copy, I wasn&amp;#39;t editing the ACL so I didn&amp;#39;t copy/paste it into a text file, I simply removed it from the router via the &amp;#39;no ip access-list...&amp;#39; command.&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;I couldn&amp;#39;t even remember what that context of the ACL was and where it was being used, it wasn&amp;#39;t applied to any interface or to the VTY lines and the vlan access-map looked fine to me.&amp;nbsp; What was I going to do?&amp;nbsp; I don&amp;#39;t back up config files manually, we have a NetMRI that does it for me, ah-hah!&amp;nbsp; I logged into our NetMRI and navigated to Network Explorer &amp;gt;&amp;nbsp; Core Router &amp;gt; Configuration Management &amp;gt; Config Explorer and downloaded the last saved config.&amp;nbsp; I was then able to decipher that the ACL in question was applied to a vlan access-map, of which when there is no ACL applied all traffic is blocked.&amp;nbsp; I quickly re-created the ACL and applied it to the corresponding map and connectivity was restored.&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;/p&gt;&lt;p&gt;Without NetMRI I could have easily deleted the vlan access-map and restored connectivity, however that would have been counterproductive to why it was there in the first place, it was there for a reason and I had to get it back.&amp;nbsp; NetMRI is a great tool that allowed me to do that by backing up my Cisco config files.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Here&amp;#39;s to not deleting ACL&amp;#39;s unless you are absolutely sure they are not in use anymore!&lt;/p&gt;&lt;p&gt;Drew &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;img src="http://www.netcordia.com/community/aggbug.aspx?PostID=1500" width="1" height="1"&gt;</description><category domain="http://www.netcordia.com/community/blogs/drews_blog/archive/tags/featured/default.aspx">featured</category></item></channel></rss>