<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access list affect in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-list-affect/m-p/4634698#M1091065</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1298088"&gt;@elliot_adlerson&lt;/a&gt; yes that is correct and by design.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference here&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="style-scope yt-formatted-string"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/A-H/asa-command-ref-A-H/clear-a-to-clear-k-commands.html#wp7335946330" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/A-H/asa-command-ref-A-H/clear-a-to-clear-k-commands.html#wp7335946330&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"When you make security policy changes to the configuration, all &lt;EM class="ph i"&gt;new&lt;/EM&gt; connections use the new security policy. &lt;EM&gt;Existing connections continue to use the policy that was configured at the time of the connection establishment&lt;/EM&gt;. To ensure that all connections use the new policy, you need to disconnect the current connections so they can reconnect using the new policy using the&lt;SPAN class="ph synph"&gt; &lt;SPAN class="keyword kwd"&gt;clear&lt;/SPAN&gt; &lt;SPAN class="keyword kwd"&gt;conn&lt;/SPAN&gt; &lt;/SPAN&gt; command."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jun 2022 07:44:18 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-06-20T07:44:18Z</dc:date>
    <item>
      <title>Access list affect</title>
      <link>https://community.cisco.com/t5/network-security/access-list-affect/m-p/4634685#M1091064</link>
      <description>&lt;P&gt;I have the following concerns regarding access lists on ASA:&lt;/P&gt;&lt;P&gt;We've permitted the computer below to access the file server and from the computer, we've opened a doc file and made some changes.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Computer (192.168.1.10) &amp;gt; ASA &amp;gt; File Server (192.168.2.3)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;while the doc file is still open on the computer, on the ASA I've changed the access list to deny but the interesting thing is the computer can still make changes to the document and save it on the file server.&lt;/P&gt;&lt;P&gt;Unless I run "clear conn address 192.168.1.10" then the access list change takes effect and block the traffic.&lt;/P&gt;&lt;P&gt;Why the ASA won't drop the traffic immediately? Is it by design? Is there any official document about this?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 07:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-affect/m-p/4634685#M1091064</guid>
      <dc:creator>elliot_adlerson</dc:creator>
      <dc:date>2022-06-20T07:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Access list affect</title>
      <link>https://community.cisco.com/t5/network-security/access-list-affect/m-p/4634698#M1091065</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1298088"&gt;@elliot_adlerson&lt;/a&gt; yes that is correct and by design.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference here&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="style-scope yt-formatted-string"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/A-H/asa-command-ref-A-H/clear-a-to-clear-k-commands.html#wp7335946330" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/A-H/asa-command-ref-A-H/clear-a-to-clear-k-commands.html#wp7335946330&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"When you make security policy changes to the configuration, all &lt;EM class="ph i"&gt;new&lt;/EM&gt; connections use the new security policy. &lt;EM&gt;Existing connections continue to use the policy that was configured at the time of the connection establishment&lt;/EM&gt;. To ensure that all connections use the new policy, you need to disconnect the current connections so they can reconnect using the new policy using the&lt;SPAN class="ph synph"&gt; &lt;SPAN class="keyword kwd"&gt;clear&lt;/SPAN&gt; &lt;SPAN class="keyword kwd"&gt;conn&lt;/SPAN&gt; &lt;/SPAN&gt; command."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 07:44:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-affect/m-p/4634698#M1091065</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-06-20T07:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Access list affect</title>
      <link>https://community.cisco.com/t5/network-security/access-list-affect/m-p/4634714#M1091066</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thanks for your reply I really appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 08:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-affect/m-p/4634714#M1091066</guid>
      <dc:creator>elliot_adlerson</dc:creator>
      <dc:date>2022-06-20T08:17:15Z</dc:date>
    </item>
  </channel>
</rss>

