<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic stateful connections ??? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633555#M1036246</link>
    <description>&lt;P&gt;hi guys, i got some prob in ASA plz help me out,, &lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;  pc1-----------ASA----------pc2&lt;/P&gt;&lt;P&gt;       outside      inside&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;  now see nat is disabled and i have given an accesslist to allow pc1 &lt;/P&gt;&lt;P&gt;to ping pc2. till here it is working fine. now suppose i have issued a&lt;/P&gt;&lt;P&gt;continuous ping from pc1 to pc 2 it goes well but meantime from CLI i removed the access list ! but the ping is still going !!!! if i stop it n&lt;/P&gt;&lt;P&gt;then issue ping again it is not going as expected, but my question is &lt;/P&gt;&lt;P&gt;why didnt it stopped when i removed the accesslist ???&lt;/P&gt;&lt;P&gt;  heres my own guess, because the connection was formed already in ASA&lt;/P&gt;&lt;P&gt;stateful table so it was allowing it to go, so is it possible that if i&lt;/P&gt;&lt;P&gt;changed or modify an access list it takes the action immediately ? is &lt;/P&gt;&lt;P&gt;there any command for that ??? becoz i m having a lot of problem in testing &lt;/P&gt;&lt;P&gt;time&lt;/P&gt;&lt;P&gt;based acls they r simply not at all working with ASA, i m using 7.0 ios &lt;/P&gt;&lt;P&gt;so&lt;/P&gt;&lt;P&gt;any help plz ???&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:02:57 GMT</pubDate>
    <dc:creator>shahidrox</dc:creator>
    <dc:date>2019-03-11T09:02:57Z</dc:date>
    <item>
      <title>stateful connections ???</title>
      <link>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633555#M1036246</link>
      <description>&lt;P&gt;hi guys, i got some prob in ASA plz help me out,, &lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;  pc1-----------ASA----------pc2&lt;/P&gt;&lt;P&gt;       outside      inside&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;  now see nat is disabled and i have given an accesslist to allow pc1 &lt;/P&gt;&lt;P&gt;to ping pc2. till here it is working fine. now suppose i have issued a&lt;/P&gt;&lt;P&gt;continuous ping from pc1 to pc 2 it goes well but meantime from CLI i removed the access list ! but the ping is still going !!!! if i stop it n&lt;/P&gt;&lt;P&gt;then issue ping again it is not going as expected, but my question is &lt;/P&gt;&lt;P&gt;why didnt it stopped when i removed the accesslist ???&lt;/P&gt;&lt;P&gt;  heres my own guess, because the connection was formed already in ASA&lt;/P&gt;&lt;P&gt;stateful table so it was allowing it to go, so is it possible that if i&lt;/P&gt;&lt;P&gt;changed or modify an access list it takes the action immediately ? is &lt;/P&gt;&lt;P&gt;there any command for that ??? becoz i m having a lot of problem in testing &lt;/P&gt;&lt;P&gt;time&lt;/P&gt;&lt;P&gt;based acls they r simply not at all working with ASA, i m using 7.0 ios &lt;/P&gt;&lt;P&gt;so&lt;/P&gt;&lt;P&gt;any help plz ???&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633555#M1036246</guid>
      <dc:creator>shahidrox</dc:creator>
      <dc:date>2019-03-11T09:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: stateful connections ???</title>
      <link>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633556#M1036249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you remove the access-list and save it the action will be taken immediately&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Dec 2006 16:59:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633556#M1036249</guid>
      <dc:creator>drolemc</dc:creator>
      <dc:date>2006-12-06T16:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: stateful connections ???</title>
      <link>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633557#M1036250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access list changes only apply to new connections initiated through the firewall.  Existing connections (prior to your changes) keep going through the firewall unless you clear them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do a 'show conn' to see what the connections are through your firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this message if it solved some/all of your question/issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2006 02:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-connections/m-p/633557#M1036250</guid>
      <dc:creator>jgervia_2</dc:creator>
      <dc:date>2006-12-07T02:23:25Z</dc:date>
    </item>
  </channel>
</rss>

