<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cisco asa packet tracer shows wrong ACL in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-packet-tracer-shows-wrong-acl/m-p/4264541#M1076924</link>
    <description>&lt;P&gt;Hi All,&lt;BR /&gt;We have cisco asa with version 9.8.3&lt;BR /&gt;While checking the packet tracer from outside source public ip to a NAT ip of a server inside the network, I could see that ACL match is on a rule where the source segments are all private.&lt;/P&gt;&lt;P&gt;So I decided to configure a rule on top of the ACL list with source as Any and destination Pvt ip and destination port. It worked perfectly.&lt;/P&gt;&lt;P&gt;My question is if I remove the deny rule, the packet tracer is still showing the same rule which do not have the source segment as my public ip (all are private).&lt;/P&gt;&lt;P&gt;I could see a bug CSCvb92548 in earlier version 9.1(7.11) 9.6(2.2), but current version is 9.8.3&lt;/P&gt;&lt;P&gt;pls help.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Dec 2020 05:14:01 GMT</pubDate>
    <dc:creator>secureIT</dc:creator>
    <dc:date>2020-12-29T05:14:01Z</dc:date>
    <item>
      <title>cisco asa packet tracer shows wrong ACL</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-packet-tracer-shows-wrong-acl/m-p/4264541#M1076924</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;We have cisco asa with version 9.8.3&lt;BR /&gt;While checking the packet tracer from outside source public ip to a NAT ip of a server inside the network, I could see that ACL match is on a rule where the source segments are all private.&lt;/P&gt;&lt;P&gt;So I decided to configure a rule on top of the ACL list with source as Any and destination Pvt ip and destination port. It worked perfectly.&lt;/P&gt;&lt;P&gt;My question is if I remove the deny rule, the packet tracer is still showing the same rule which do not have the source segment as my public ip (all are private).&lt;/P&gt;&lt;P&gt;I could see a bug CSCvb92548 in earlier version 9.1(7.11) 9.6(2.2), but current version is 9.8.3&lt;/P&gt;&lt;P&gt;pls help.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 05:14:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-packet-tracer-shows-wrong-acl/m-p/4264541#M1076924</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2020-12-29T05:14:01Z</dc:date>
    </item>
  </channel>
</rss>

