<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic stateful connections ??? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633597#M1036237</link>
    <description>&lt;P&gt;hi guys, i got some prob in ASA plz help me out,, &lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;  pc1-----------ASA----------pc2&lt;/P&gt;&lt;P&gt;       outside      inside&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;  now see nat is disabled and i have given an accesslist to allow pc1 &lt;/P&gt;&lt;P&gt;to ping pc2. till here it is working fine. now suppose i have issued a&lt;/P&gt;&lt;P&gt;continuous ping from pc1 to pc 2 it goes well but meantime from CLI i removed the access list ! but the ping is still going !!!! if i stop it n&lt;/P&gt;&lt;P&gt;then issue ping again it is not going as expected, but my question is &lt;/P&gt;&lt;P&gt;why didnt it stopped when i removed the accesslist ???&lt;/P&gt;&lt;P&gt;  heres my own guess, because the connection was formed already in ASA&lt;/P&gt;&lt;P&gt;stateful table so it was allowing it to go, so is it possible that if i&lt;/P&gt;&lt;P&gt;changed or modify an access list it takes the action immediately ? is &lt;/P&gt;&lt;P&gt;there any command for that ??? becoz i m having a lot of problem in testing &lt;/P&gt;&lt;P&gt;time&lt;/P&gt;&lt;P&gt;based acls they r simply not at all working with ASA, i m using 7.0 ios &lt;/P&gt;&lt;P&gt;so&lt;/P&gt;&lt;P&gt;any help plz ???&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:03:00 GMT</pubDate>
    <dc:creator>shahidrox</dc:creator>
    <dc:date>2019-03-11T09:03:00Z</dc:date>
    <item>
      <title>stateful connections ???</title>
      <link>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633597#M1036237</link>
      <description>&lt;P&gt;hi guys, i got some prob in ASA plz help me out,, &lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;  pc1-----------ASA----------pc2&lt;/P&gt;&lt;P&gt;       outside      inside&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;  now see nat is disabled and i have given an accesslist to allow pc1 &lt;/P&gt;&lt;P&gt;to ping pc2. till here it is working fine. now suppose i have issued a&lt;/P&gt;&lt;P&gt;continuous ping from pc1 to pc 2 it goes well but meantime from CLI i removed the access list ! but the ping is still going !!!! if i stop it n&lt;/P&gt;&lt;P&gt;then issue ping again it is not going as expected, but my question is &lt;/P&gt;&lt;P&gt;why didnt it stopped when i removed the accesslist ???&lt;/P&gt;&lt;P&gt;  heres my own guess, because the connection was formed already in ASA&lt;/P&gt;&lt;P&gt;stateful table so it was allowing it to go, so is it possible that if i&lt;/P&gt;&lt;P&gt;changed or modify an access list it takes the action immediately ? is &lt;/P&gt;&lt;P&gt;there any command for that ??? becoz i m having a lot of problem in testing &lt;/P&gt;&lt;P&gt;time&lt;/P&gt;&lt;P&gt;based acls they r simply not at all working with ASA, i m using 7.0 ios &lt;/P&gt;&lt;P&gt;so&lt;/P&gt;&lt;P&gt;any help plz ???&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633597#M1036237</guid>
      <dc:creator>shahidrox</dc:creator>
      <dc:date>2019-03-11T09:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: stateful connections ???</title>
      <link>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633598#M1036239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're right. It will still pinging because the connection table for the existing ping session is still active. It will only gone if you manually stop the ping or issue 'cle xlate' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the 'clear xlate' everytime you want to clear the connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/ps6120/products_command_reference_chapter09186a008063f0de.html#wp2029296" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/ps6120/products_command_reference_chapter09186a008063f0de.html#wp2029296&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Dec 2006 03:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633598#M1036239</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-12-03T03:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: stateful connections ???</title>
      <link>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633599#M1036241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;but dont u think this is inconvenient ?? like if there are 2 outside users connected to my webserver n i want to block 1 of them so i designed an acl but if i clear xlate then both of the connections will be reset !!! is there any other way&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Dec 2006 11:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633599#M1036241</guid>
      <dc:creator>shahidrox</dc:creator>
      <dc:date>2006-12-03T11:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: stateful connections ???</title>
      <link>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633600#M1036242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another way is to use "clear local-host &lt;LOCAL-HOST_INTERNAL_IP&gt;" command.&lt;/LOCAL-HOST_INTERNAL_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWALL#clear local-host 10.1.1.15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will clear the network state of a local host stops all network connections and xlates that are associated ONLY with the local hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Dec 2006 13:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633600#M1036242</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-12-03T13:35:30Z</dc:date>
    </item>
  </channel>
</rss>

