mirror of
https://github.com/fwbuilder/fwbuilder
synced 2025-10-16 15:38:43 +02:00
rule element by name after group is expanded, this helps ensure stable ordering of objects in generated configuration. * Compiler.cpp (replaceClusterInterfaceInItfRE::processNext): sorting objects in rule element after cluster interfaces have been replaced, this helps ensure stable ordering of objects in generated configuration. * FWObject.h (FWObjectNameCmpPredicate): moved this class from gui-specific module to libfwbuilder as it is universally useful. It can compare FWObject objects by name and can optionally can follow references; it can be used with std::sort() to sort lists of FWObject pointers or directly sort rule elements.
213 lines
4.4 KiB
Plaintext
Executable File
213 lines
4.4 KiB
Plaintext
Executable File
!
|
|
! This is automatically generated file. DO NOT MODIFY !
|
|
!
|
|
! Firewall Builder fwb_iosacl v4.2.0.3499
|
|
!
|
|
! Generated Sat Mar 12 19:44:07 2011 PST by vadim
|
|
!
|
|
! Compiled for iosacl 12.3
|
|
!
|
|
!# files: * testios20-v12.3.fw
|
|
!
|
|
|
|
! testios20-v12.3:Policy:10: error: IP options match requires IOS v12.4 or later.
|
|
! testios20-v12.3:Policy:10: error: IP options match requires IOS v12.4 or later.
|
|
! testios20-v12.3:Policy:10: error: IP options match requires IOS v12.4 or later.
|
|
! testios20-v12.3:Policy:10: error: IP options match requires IOS v12.4 or later.
|
|
! testios20-v12.3:Policy:11: error: IP options match requires IOS v12.4 or later.
|
|
|
|
!
|
|
! Prolog script:
|
|
!
|
|
|
|
!
|
|
! End of prolog script:
|
|
!
|
|
|
|
hostname testios20-v12.3
|
|
|
|
no ip access-list extended e0_in
|
|
no ip access-list extended e0_out
|
|
no ip access-list extended e1_in
|
|
no ip access-list extended e1_out
|
|
|
|
! ================ IPv4
|
|
|
|
|
|
ip access-list extended e0_in
|
|
!
|
|
! Rule 0 (global)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 2 (ethernet0)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 3 (global)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 5 (ethernet0)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 6 (global)
|
|
permit ip any any tos 16
|
|
!
|
|
! Rule 7 (global)
|
|
permit ip any any dscp 16
|
|
!
|
|
! Rule 8 (global)
|
|
permit ip any any dscp af11
|
|
!
|
|
! Rule 9 (global)
|
|
permit ip any any dscp 16
|
|
permit ip any any dscp af11
|
|
!
|
|
! Rule 10 (ethernet0)
|
|
permit ip any any option lsr
|
|
permit ip any any option record-route
|
|
permit ip any any option ssr
|
|
permit ip any any
|
|
!
|
|
! Rule 11 (ethernet0)
|
|
permit ip any any option any-options
|
|
!
|
|
! Rule 12 (global)
|
|
permit ip any any
|
|
!
|
|
! Rule 13 (global)
|
|
deny ip any any log
|
|
exit
|
|
|
|
ip access-list extended e0_out
|
|
!
|
|
! Rule 2 (ethernet0)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 6 (global)
|
|
permit ip any any tos 16
|
|
!
|
|
! Rule 7 (global)
|
|
permit ip any any dscp 16
|
|
!
|
|
! Rule 8 (global)
|
|
permit ip any any dscp af11
|
|
!
|
|
! Rule 9 (global)
|
|
permit ip any any dscp 16
|
|
permit ip any any dscp af11
|
|
!
|
|
! Rule 12 (global)
|
|
permit ip any any
|
|
!
|
|
! Rule 13 (global)
|
|
deny ip any any log
|
|
exit
|
|
|
|
ip access-list extended e1_in
|
|
!
|
|
! Rule 0 (global)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 1 (ethernet1)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 3 (global)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 4 (ethernet1)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 6 (global)
|
|
permit ip any any tos 16
|
|
!
|
|
! Rule 7 (global)
|
|
permit ip any any dscp 16
|
|
!
|
|
! Rule 8 (global)
|
|
permit ip any any dscp af11
|
|
!
|
|
! Rule 9 (global)
|
|
permit ip any any dscp 16
|
|
permit ip any any dscp af11
|
|
!
|
|
! Rule 12 (global)
|
|
permit ip any any
|
|
!
|
|
! Rule 13 (global)
|
|
deny ip any any log
|
|
exit
|
|
|
|
ip access-list extended e1_out
|
|
!
|
|
! Rule 0 (global)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 1 (ethernet1)
|
|
permit ip any 10.10.10.0 0.0.0.255
|
|
permit ip any 10.10.11.0 0.0.0.255
|
|
permit ip any 10.10.12.0 0.0.0.255
|
|
!
|
|
! Rule 6 (global)
|
|
permit ip any any tos 16
|
|
!
|
|
! Rule 7 (global)
|
|
permit ip any any dscp 16
|
|
!
|
|
! Rule 8 (global)
|
|
permit ip any any dscp af11
|
|
!
|
|
! Rule 9 (global)
|
|
permit ip any any dscp 16
|
|
permit ip any any dscp af11
|
|
!
|
|
! Rule 12 (global)
|
|
permit ip any any
|
|
!
|
|
! Rule 13 (global)
|
|
deny ip any any log
|
|
exit
|
|
|
|
|
|
interface ethernet0
|
|
ip access-group e0_in in
|
|
exit
|
|
interface ethernet0
|
|
ip access-group e0_out out
|
|
exit
|
|
interface ethernet1
|
|
ip access-group e1_in in
|
|
exit
|
|
interface ethernet1
|
|
ip access-group e1_out out
|
|
exit
|
|
|
|
|
|
|
|
|
|
|
|
!
|
|
! Epilog script:
|
|
!
|
|
|
|
! End of epilog script:
|
|
!
|