sandbox/cisco/policies_samples/1

8 lines
3.1 KiB
Text

Start
^access\-list\s+cached\s+ACL* -> NoRecord
^\s+alert\-interval* -> NoRecord
^access\-list\s+${ACL_NAME};\s+${ACL_TOT_ELEM}\s+elements;\s+name\s+hash:\s+${ACL_NAME_HASH}\s* -> Record
^access\-list\s+${ACL_NAME}\s+line\s+${LINE_NUM}\s+${TYPE}\s+${ACTION}\s+(${PROTOCOL}|object\s+${SVC_OBJECT}|object\-group\s+${SVC_OBJECT_GRP}+)\s+(user\s+${USER}\s+|object\-group\-user\s+${USER_GROUP}\s+){0,1}(object\-group\-security\s+${SRC_SECURITY_GROUP_NAME}\s+){0,1}(interface\s+${SRC_INTFC}|object\-group\s+${SRC_OBJECT_GRP}|object\s+${SRC_OBJECT}|host\s+${SRC_HOST}|${SRC_NETWORK}\s+${SRC_MASK}|${SRC_ANY})\s+((eq\s+${SRC_PORT}|lt\s+${SRC_PORT_LESS_THAN}|gt\s+${SRC_PORT_GREATER_THAN}|range\s+${SRC_PORT_RANGE_START}\s+${SRC_PORT_RANGE_END}|object\-group\s+${SRC_PORT_GRP}|object\s+${SRC_PORT_OBJECT})\s+){0,1}(object\-group\-security\s+${DST_SECURITY_GROUP}\s+){0,1}(interface\s+${DST_INTFC}|object\-group\s+${DST_OBJECT_GRP}|object\s+${DST_OBJECT}|host\s+${DST_HOST}|${DST_NETWORK}\s+${DST_MASK}|${DST_ANY})\s+((eq\s+${DST_PORT}|lt\s+${DST_PORT_LESS_THAN}|gt\s+${DST_PORT_GREATER_THAN}|range\s+${DST_PORT_RANGE_START}\s+${DST_PORT_RANGE_END}|object\-group\s+${DST_PORT_GRP}|object\s+${DST_PORT_OBJECT})\s+){0,1}(${ICMP_KEY_VALUE}(\s+${ICMP_VALUE})?\s+){0,1}((log\s+(${LOG_LEVEL}\s+interval\s+${LOG_INTERVAL}|disable|default))\s+){0,1}(time\-range\s+${TIME_RANGE}\s+){0,1}(${ACE_STATE}\s+){0,1}\(hitcnt=${HIT_COUNT}\)\s+(\(inactive\)\s+){0,1}${LINE_HASH}\s* -> Record
^\s+access\-list\s* -> NoRecord
^access-list\s+${ACL_NAME}\s+line\s+${LINE_NUM}\s+remark\s+${REMARK}\s* -> Record
^.* -> Error "Did not match any rules"