<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SGACLs SGT CTS What order are the rules processed and are they stateful/stateless in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sgacls-sgt-cts-what-order-are-the-rules-processed-and-are-they/m-p/3491066#M494926</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;a) The ASA Firewall does not use SGACLs. The ASA can however make use of Security Groups and SGT in policies configured at the ASA. This is known as Security Group Firewall. SGACLs are role-based policies with further granularity provided by Access Control Entries within the SGACL. These are configured at ISE and distributed to switches today and other devices such as routers in the very near future. When a policy is created at the ASA (SGFW), they are stateful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b) SGACLs in IOS are processed at egress. If a standard ACL and an SGACL are both present, the standard ACL is processed first and then the SGACL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Oct 2016 18:33:06 GMT</pubDate>
    <dc:creator>mjessup</dc:creator>
    <dc:date>2016-10-14T18:33:06Z</dc:date>
    <item>
      <title>SGACLs SGT CTS What order are the rules processed and are they stateful/stateless</title>
      <link>https://community.cisco.com/t5/network-access-control/sgacls-sgt-cts-what-order-are-the-rules-processed-and-are-they/m-p/3491065#M494916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;Could any one please confirm my following assumptions about the processing of SGACLs.&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;&lt;SPAN style="font-size: 14.4px;"&gt;a) SGACLs on a ASA firewall are stateful and processed as normal ACL's on a per interface basis ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;&lt;SPAN style="font-size: 14.4px;"&gt;b) SGACLs on IOS are processed&amp;nbsp; after normal&amp;nbsp; Ingress ACL'a and before Egress ACL's and are stateless ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;&lt;SPAN style="font-size: 14.4px;"&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgacls-sgt-cts-what-order-are-the-rules-processed-and-are-they/m-p/3491065#M494916</guid>
      <dc:creator>gtuthill</dc:creator>
      <dc:date>2019-03-11T07:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: SGACLs SGT CTS What order are the rules processed and are they stateful/stateless</title>
      <link>https://community.cisco.com/t5/network-access-control/sgacls-sgt-cts-what-order-are-the-rules-processed-and-are-they/m-p/3491066#M494926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;a) The ASA Firewall does not use SGACLs. The ASA can however make use of Security Groups and SGT in policies configured at the ASA. This is known as Security Group Firewall. SGACLs are role-based policies with further granularity provided by Access Control Entries within the SGACL. These are configured at ISE and distributed to switches today and other devices such as routers in the very near future. When a policy is created at the ASA (SGFW), they are stateful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b) SGACLs in IOS are processed at egress. If a standard ACL and an SGACL are both present, the standard ACL is processed first and then the SGACL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2016 18:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgacls-sgt-cts-what-order-are-the-rules-processed-and-are-they/m-p/3491066#M494926</guid>
      <dc:creator>mjessup</dc:creator>
      <dc:date>2016-10-14T18:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: SGACLs SGT CTS What order are the rules processed and are they stateful/stateless</title>
      <link>https://community.cisco.com/t5/network-access-control/sgacls-sgt-cts-what-order-are-the-rules-processed-and-are-they/m-p/3491067#M494943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah Mike!   Thanks for responding to the community question.  I was just talking with Kevin R after our team meeting about getting more attention in the community!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keti&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2016 19:53:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgacls-sgt-cts-what-order-are-the-rules-processed-and-are-they/m-p/3491067#M494943</guid>
      <dc:creator>kilcreas</dc:creator>
      <dc:date>2016-10-14T19:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: SGACLs SGT CTS What order are the rules processed and are they stateful/stateless</title>
      <link>https://community.cisco.com/t5/network-access-control/sgacls-sgt-cts-what-order-are-the-rules-processed-and-are-they/m-p/3491068#M494953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for your response to my question, very much appreciated.&lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2016 20:24:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgacls-sgt-cts-what-order-are-the-rules-processed-and-are-they/m-p/3491068#M494953</guid>
      <dc:creator>gtuthill</dc:creator>
      <dc:date>2016-10-14T20:24:59Z</dc:date>
    </item>
  </channel>
</rss>

