Cisco ACL Analyzer
Analyze Cisco IOS / IOS-XE IPv4 access lists for structure, duplicates, shadowing, broad permits, risky services, unreachable rules, and likely cleanup opportunities.
ACL Input
Executive Summary
Findings
Parsed Rules
| ACL | Seq | Action | Protocol | Source | Destination | Service | Options | Risk |
|---|
Traffic Match Simulator
Test a hypothetical IPv4 flow against the parsed rules. First-match logic is used within the selected ACL. Object-groups that are not expanded may produce an indeterminate result.
How to use the analyzer
Copy the relevant show running-config | section access-list, named ACL section, or sanitized configuration.
Paste the ACL and select Analyze ACL. Review parse warnings before relying on findings.
Prioritize broad permits, exposed management services, duplicate entries, complete shadows and rules after unconditional termination.
Test representative source/destination/protocol/port combinations against first-match behavior.
Confirm ACL direction, interface, routing, NAT order, object-groups, platform behavior and current traffic before editing.
Use configuration review, peer approval, backups, rollback plans and post-change verification.
Examples
Internet-facing HTTPS ACL
ip access-list extended INTERNET-IN 10 permit tcp any host 203.0.113.10 eq 443 20 deny ip any any log
Management ACL
ip access-list standard MGMT-SOURCES 10 permit 10.20.30.0 0.0.0.255 20 deny any log
Potential shadowing
ip access-list extended APP 10 permit ip 10.0.0.0 0.255.255.255 any 20 permit tcp host 10.10.10.20 host 172.16.1.20 eq 443 30 deny ip any any
Warnings & limitations
- This analyzer performs static, local configuration analysis. It does not read device state, routing tables, NAT tables, interface bindings, session tables, counters or live traffic.
- Shadowing and overlap detection is strongest for IPv4 addresses expressed as
any,host, and contiguous wildcard masks. Non-contiguous wildcard masks are treated conservatively. - Object-group references are identified but not recursively resolved unless their members are present in a supported form. Results involving unresolved groups are marked accordingly.
- Service names are mapped to common ports for convenience. Device-specific aliases or customized services may differ.
- An
establishedTCP entry is interpreted only as a rule option; the analyzer does not emulate every platform-specific TCP flag behavior. - Rule risk is contextual. A broad permit may be intentional inside a trusted segment, while a narrow rule may still be unsafe in the wrong location.
- Do not paste secrets, credentials, private keys or unrelated confidential configuration. Sanitize configurations before using any browser-based analysis tool on shared systems.
Your feedback matters