- Community Home
- >
- Networking
- >
- Switching and Routing
- >
- Comware Based
- >
- Want to Remove ACL
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2021 11:20 PM - last edited on 08-05-2021 12:40 AM by support_s
08-03-2021 11:20 PM - last edited on 08-05-2021 12:40 AM by support_s
Hi,
I have HPE-5510 switch configured with ACL. Since in ACL I have configured that the switch should be accessible only from the mentioned IPs. But now since I have to migrate switch to other location, I need to remove ACL, I tried it but then switch becomes inaccessible.
Kindly advise as to how to remove ACL and its rules so that I can access Switch from any PC ?
Here is the configuration of ACL
acl number 3012
rule 5 permit ip source 172.16.12.62 0
rule 10 permit ip source 172.16.12.66 0
rule 15 permit ip source 172.16.12.0 0.0.0.127 destination 172.16.11.1 0
rule 20 permit ip source 172.16.12.0 0.0.0.127 destination 172.16.11.11 0
rule 25 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.2 0
rule 30 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.3 0
rule 35 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.4 0
rule 40 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.7 0
rule 50 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.10 0
rule 55 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.13.0 0.0.0.15
rule 60 permit ip
Manish
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2021 11:49 PM
08-03-2021 11:49 PM
Re: Want to Remove ACL
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-04-2021 12:58 AM
08-04-2021 12:58 AM
Re: Want to Remove ACL
Hi @ManishChawda, as suggested by @Ivan_B where the ACL number 3012 was applied?
Please post the output of these three commands:
display acl all
display acl 3012
display packet-filter
I'm not an HPE Employee

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-04-2021 03:54 AM
08-04-2021 03:54 AM
Re: Want to Remove ACL
Hi,
ACL is applied in L3 Switch HPE-5510 to all PC's except 2 PC's so that only from that 2 PC's I can access HPE-5510. Kindly advise.
Below is the output.
[UMHPE5510L3-112]display acl all
Advanced IPv4 ACL 3012, 12 rules,
ACL's step is 5, start ID is 0
rule 5 permit ip source 172.16.12.31 0
rule 6 permit ip source 172.16.12.32 0
rule 10 permit ip source 172.16.12.66 0
rule 15 permit ip source 172.16.12.0 0.0.0.127 destination 172.16.11.1 0
rule 20 permit ip source 172.16.12.0 0.0.0.127 destination 172.16.11.11 0
rule 25 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.2 0
rule 30 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.3 0
rule 35 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.4 0
rule 40 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.7 0
rule 50 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.10 0
rule 55 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.13.0 0.0.0.15
rule 60 permit ip
-----------
[UMHPE5510L3-112]display acl 3012
Advanced IPv4 ACL 3012, 12 rules,
ACL's step is 5, start ID is 0
rule 5 permit ip source 172.16.12.31 0
rule 6 permit ip source 172.16.12.32 0
rule 10 permit ip source 172.16.12.66 0
rule 15 permit ip source 172.16.12.0 0.0.0.127 destination 172.16.11.1 0
rule 20 permit ip source 172.16.12.0 0.0.0.127 destination 172.16.11.11 0
rule 25 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.2 0
rule 30 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.3 0
rule 35 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.4 0
rule 40 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.7 0
rule 50 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.10 0
rule 55 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.13.0 0.0.0.15
rule 60 permit ip
---------
[UMHPE5510L3-112]display packet-filter interface
Interface: Vlan-interface12
Inbound policy:
IPv4 ACL 3012
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-04-2021 07:00 AM
08-04-2021 07:00 AM
Re: Want to Remove ACL
TBH I don't see how removing the ACL 3012 can block access to anything. Not sure what steps did you follow to remove it, but I would try:
system-view
interface Vlan12
undo packet-filter 3012 inbound
and test. At this time do not remove the ACL itself. If everything is fine after running abovementioned commands, then remove the ACL itself by:
system-view
undo acl number 3012
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-04-2021 09:32 AM
08-04-2021 09:32 AM
Re: Want to Remove ACL
At first you need to remove the qos-profile from the interfaces where the rule is applied; before you need to delete the ACL binded to the qos-profile and then you could delete the ACL, if needed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-05-2021 03:34 AM
08-05-2021 03:34 AM
Re: Want to Remove ACL
Hi,
Thanks for the reply.
This was configured by one of the partner. I will surely try but since I am at remote location so when I will physically visit the location I will try. I will update you ASAP.
One more thing, can you give me commands to configure the same ACL step-by-step.
Manish
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-05-2021 05:29 AM
08-05-2021 05:29 AM
Re: Want to Remove ACL
In order to configure same ACL with same number use following commands:
system-view
acl number 3012
rule 5 permit ip source 172.16.12.31 0
rule 6 permit ip source 172.16.12.32 0
rule 10 permit ip source 172.16.12.66 0
rule 15 permit ip source 172.16.12.0 0.0.0.127 destination 172.16.11.1 0
rule 20 permit ip source 172.16.12.0 0.0.0.127 destination 172.16.11.11 0
rule 25 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.2 0
rule 30 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.3 0
rule 35 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.4 0
rule 40 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.7 0
rule 50 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.11.10 0
rule 55 deny ip source 172.16.12.0 0.0.0.127 destination 172.16.13.0 0.0.0.15
rule 60 permit ip
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-05-2021 06:29 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2021 12:27 AM
08-06-2021 12:27 AM
Re: Want to Remove ACL
Hi,
Thanks for all!. I will try once visiting the location and update you till then kudos and accepting solution.
Thanks