Deleting Rules from ACLs

To delete rules from an IPv4, IPv6, or MAC ACL, complete the following steps.
  1. Enter the configure terminal command to access global configuration mode.
    device# configure terminal
    
  2. Enter ACL configuration sub-mode for the IPv4, IPv6, or MAC ACL you want to modify.
    device(config)# ip access-list standard ip_acl_1
    
    device(config)# ipv6 access-list ipv6_acl_1
    
    device(config)# mac access-list macdata
  3. If needed, enter the appropriate show command to display the rules of the relevant ACL.
    • Enter the show ip access-lists command followed by the name of an IPv4 ACL.
    • Enter the show ipv6 access-lists command followed by the name of an IPv6 ACL.
    • Enter the show mac access-lists command followed by the name of a MAC ACL.
    device(config-std-ipacl-ip_acl_1)# show ip access-lists ip_acl_1
    Standard IP access list ip_acl_1: 3 entries
    10: permit 1.1.1.0  0.0.0.255
    11: permit host 2.2.2.1 
    20: deny   2.2.2.0  0.0.0.255
    
  4. Remove the rule in one of the following ways:
    • To delete a rule by sequence number, enter the no sequence command, specifying the sequence number.
      device(config-std-ipacl-ip_acl_1)# no sequence 11
      
    • To delete a rule by content, enter the no permit command, specifying the rule content.
      device(config-std-ipacl-ip_acl_1)# no permit host 2.2.2.1
      
  5. If you want to clean up the sequence numbers, for example, so that you can re-use a sequence number that you have deleted, enter the regenerate-seq-number command.
    device(config-std-ipacl-ip_acl_1)# regenerate-seq-number