Problem removing access-list

Oct 29, 2006 9 Replies

I've accidently made an IP Named ACL with spaces inside:



ip access-list extended admin on vty0 (10.0.0.1)



Now I'm unable to delete this ACL. Is there any better way than purging my running config and restore from tftp?



BR, PIT


Please tell which process do you followed to remove this ACL for ?? Router/PIX

Ck

Peter Allgeyer wrote:

Tried: hostname(config)#no ip access-list extended admin on vty0 (10.0.0.1) ^ % Invalid input detected at '^' marker.

hostname(config)#no ip access-list extended "admin on vty0 (10.0.0.1)" ^ % Invalid input detected at '^' marker.

hostname(config)#no ip access-list extended 'admin on vty0 (10.0.0.1)' ^ % Invalid input detected at '^' marker.

hostname(config)#no ip access-list extended admin\\ on\\ vty0\\ (10.0.0.1) hostname(config)#no ip access-list extended admin\\ on\\ vty0\\ \\(10\\.0\\.0\\.1\\)

No success. Device is Cat6509 IOS 12.2.

BR, PIT

Peter Allgeyer crashed Echelon writing news:8p8f14- snipped-for-privacy@pitweb.dyndns.org:

aren't in supposed to be access-class

no access-class admin on vty0

Does this access-list is mapped to any specific interface. If yes then please remove that first then try removing this ACL.

CK

Peter Allgeyer wrote:

Maybe a week too late however:-

What about a GUI?

I am confused exactly how to get what but there seems to be several options

conf t ip http server

browse to router.

Out of interest how did you create it?

Hmm, have to check that. A GUI on a 6509?

Really good question. Don't know how exactly. It was an accident by using cut and paste (left mouse button, cut - middle mouse button paste). I was really suprised, too, that such a configuration line is possible.

I haven't solved it. I'm thinking about asking cisco support about that, but I'm worrying that they also don't know any other solution than writing a "clean" config back from tftp server (and I wanted to avoid a reboot).

BR, PIT

Are you any further behind if that is the only solution they come up with? At least you'd know to stop experimenting and just queue it up for the next reboot, and they might have an answer after all.

I don't know because I haven't asked Cisco yet.

That's exactly what I am doing. Thanks.

BR, PIT

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required