<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic can you do packet-tracer from in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-rules-order-acl/m-p/2981521#M144096</link>
    <description>&lt;P&gt;can you do packet-tracer from outside low to high interface host ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;share configuration as well .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks ,&lt;/P&gt;
&lt;P&gt;Mani&lt;/P&gt;</description>
    <pubDate>Tue, 20 Dec 2016 10:30:20 GMT</pubDate>
    <dc:creator>MANI .P</dc:creator>
    <dc:date>2016-12-20T10:30:20Z</dc:date>
    <item>
      <title>Problem with Rules Order ACL</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-rules-order-acl/m-p/2981519#M144090</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I have a ASA 5545 with version 9.4(2)11 in routed mode&lt;/P&gt;
&lt;P&gt;And I have problems with the Global ACL.&lt;/P&gt;
&lt;P&gt;I started with ACL's on the interfaces and that works fine. I put an ACL's on the interfaces with the lowest security&amp;nbsp;and I use the ASA default that traffic is possible from a higher security interface to a lower security interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I have now build also Global ACL's and the problem is that the traffic from the higher security interface to the lower security interface is not working anymore.&lt;/P&gt;
&lt;P&gt;It works only when I create in the Global ACL the rule permit any any , just before the deny any any rule.&lt;/P&gt;
&lt;P&gt;When I read the documentation I think the order of rules is&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;1e &amp;nbsp;Traffic from an higher security interface to lower security interface.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;2e &amp;nbsp;Interface ACL&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;3e &amp;nbsp;Global ACL&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P&gt;What could be the problem ?&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:40:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-rules-order-acl/m-p/2981519#M144090</guid>
      <dc:creator>r.vanschendel</dc:creator>
      <dc:date>2019-03-12T08:40:46Z</dc:date>
    </item>
    <item>
      <title>The moment there is an ACL in</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-rules-order-acl/m-p/2981520#M144093</link>
      <description>&lt;P&gt;The moment there is an ACL in place in a particular direction, the default behavior is not used any more. And if you have configured a rule in the global ACL, then&amp;nbsp;traffic entering the ASA on any interface is subject to the ACLs and defaults are ignored.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 19:00:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-rules-order-acl/m-p/2981520#M144093</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-12-19T19:00:14Z</dc:date>
    </item>
    <item>
      <title>can you do packet-tracer from</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-rules-order-acl/m-p/2981521#M144096</link>
      <description>&lt;P&gt;can you do packet-tracer from outside low to high interface host ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;share configuration as well .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks ,&lt;/P&gt;
&lt;P&gt;Mani&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2016 10:30:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-rules-order-acl/m-p/2981521#M144096</guid>
      <dc:creator>MANI .P</dc:creator>
      <dc:date>2016-12-20T10:30:20Z</dc:date>
    </item>
  </channel>
</rss>

