<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Access List says allowed, but traffic doesn't pass..Help! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959251#M144618</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have just installed a new firewall 5506X running:-&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cisco Adaptive Security Appliance Software Version 9.6(1)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Device Manager Version 7.6(1)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And it has various routes to an MPLS:-&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 140.85.0.0 255.255.0.0 [1/0] via 10.164.115.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 141.143.0.0 255.255.0.0 [1/0] via 10.164.115.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 159.166.0.0 255.255.0.0 [1/0] via 10.164.115.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 162.130.0.0 255.255.0.0 [1/0] via 10.164.115.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 162.130.196.128 255.255.255.255 [1/0] via 62.232.113.153, outside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 162.130.196.190 255.255.255.255 [1/0] via 62.232.113.153, outside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 162.130.196.219 255.255.255.255 [1/0] via 62.232.113.153, outside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 162.130.197.157 255.255.255.255 [1/0] via 62.232.113.153, outside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;C&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 172.16.0.0 255.255.255.0 is directly connected, Associate_VoIP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;L&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 172.16.0.1 255.255.255.255 is directly connected, Associate_VoIP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;C&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.21.0 255.255.255.0 is directly connected, KEY-CARD-NET&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;L&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.21.1 255.255.255.255 is directly connected, KEY-CARD-NET&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.72.0 255.255.252.0 [1/0] via 10.164.95.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.114.0 255.255.255.0 [1/0] via 10.164.95.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I can route traffic to the all of the IP's in the routing table bar the 192.168.7x.x subnets even though the access list allows the traffic to pass:-&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: CAPTURE&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MAC Access list&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: ACCESS-LIST&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Implicit Rule&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MAC Access list&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: ROUTE-LOOKUP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype: Resolve Egress Interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;found next-hop 10.164.95.97 using egress ifc&amp;nbsp; LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 4 &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: ROUTE-LOOKUP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype: Resolve Egress Interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;found next-hop 10.164.114.3 using egress ifc&amp;nbsp; ASSOCIATES_VLAN300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: NAT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype: per-session&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 6&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: IP-OPTIONS&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 7&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: NAT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype: per-session&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: IP-OPTIONS&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 9&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: FLOW-CREATION&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;New flow created with id 23292388, packet dispatched to next module&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;input-interface: ASSOCIATES_VLAN300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;input-status: up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;input-line-status: up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;output-interface: LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;output-status: up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;output-line-status: up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Action: allow&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If i try to ping, i get nothing a all from the server, however, on another firewall running&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;9.5(2) we&amp;nbsp;don't have the issue, its the same configuration and access-list apart from the internal addressing and that works fine.. I am at a loss as to why it doesn't work on the&amp;nbsp;latest software?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Working on 9.5.2:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TCP Ping [n]: y&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Interface: ASSOCIATES_VLAN300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Target IP address: 192.168.72.96&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Destination port: [80]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Specify source? [n]:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Repeat count: [5]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Timeout in seconds: [2]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No source specified. Pinging from identity interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sending 5 TCP SYN requests to 192.168.72.96 port 80&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;from 10.164.95.98, timeout is 2 seconds:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!!!!!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 91/95/107 ms&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Failed on 9.6:-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TCP Ping [n]: y&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Interface: ASSOCIATES_VLAN300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Target IP address: 192.168.72.96&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Destination port: [80]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Specify source? [n]:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Repeat count: [5]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Timeout in seconds: [2]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No source specified. Pinging from identity interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sending 5 TCP SYN requests to 192.168.72.96 port 80&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;from 10.164.115.98, timeout is 2 seconds:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;?????&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Success rate is 0 percent (0/5)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any Help you can&amp;nbsp;give to diagnose this issue is&amp;nbsp;greatly&amp;nbsp;received.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:35:18 GMT</pubDate>
    <dc:creator>Chris Bloy</dc:creator>
    <dc:date>2019-03-12T08:35:18Z</dc:date>
    <item>
      <title>Access List says allowed, but traffic doesn't pass..Help!</title>
      <link>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959251#M144618</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have just installed a new firewall 5506X running:-&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cisco Adaptive Security Appliance Software Version 9.6(1)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Device Manager Version 7.6(1)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And it has various routes to an MPLS:-&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 140.85.0.0 255.255.0.0 [1/0] via 10.164.115.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 141.143.0.0 255.255.0.0 [1/0] via 10.164.115.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 159.166.0.0 255.255.0.0 [1/0] via 10.164.115.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 162.130.0.0 255.255.0.0 [1/0] via 10.164.115.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 162.130.196.128 255.255.255.255 [1/0] via 62.232.113.153, outside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 162.130.196.190 255.255.255.255 [1/0] via 62.232.113.153, outside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 162.130.196.219 255.255.255.255 [1/0] via 62.232.113.153, outside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 162.130.197.157 255.255.255.255 [1/0] via 62.232.113.153, outside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;C&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 172.16.0.0 255.255.255.0 is directly connected, Associate_VoIP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;L&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 172.16.0.1 255.255.255.255 is directly connected, Associate_VoIP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;C&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.21.0 255.255.255.0 is directly connected, KEY-CARD-NET&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;L&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.21.1 255.255.255.255 is directly connected, KEY-CARD-NET&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.72.0 255.255.252.0 [1/0] via 10.164.95.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.114.0 255.255.255.0 [1/0] via 10.164.95.97, LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I can route traffic to the all of the IP's in the routing table bar the 192.168.7x.x subnets even though the access list allows the traffic to pass:-&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: CAPTURE&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MAC Access list&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: ACCESS-LIST&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Implicit Rule&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MAC Access list&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: ROUTE-LOOKUP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype: Resolve Egress Interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;found next-hop 10.164.95.97 using egress ifc&amp;nbsp; LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 4 &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: ROUTE-LOOKUP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype: Resolve Egress Interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;found next-hop 10.164.114.3 using egress ifc&amp;nbsp; ASSOCIATES_VLAN300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: NAT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype: per-session&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 6&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: IP-OPTIONS&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 7&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: NAT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype: per-session&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: IP-OPTIONS&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Phase: 9&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type: FLOW-CREATION&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Subtype:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;New flow created with id 23292388, packet dispatched to next module&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Result:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;input-interface: ASSOCIATES_VLAN300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;input-status: up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;input-line-status: up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;output-interface: LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;output-status: up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;output-line-status: up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Action: allow&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If i try to ping, i get nothing a all from the server, however, on another firewall running&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;9.5(2) we&amp;nbsp;don't have the issue, its the same configuration and access-list apart from the internal addressing and that works fine.. I am at a loss as to why it doesn't work on the&amp;nbsp;latest software?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Working on 9.5.2:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TCP Ping [n]: y&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Interface: ASSOCIATES_VLAN300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Target IP address: 192.168.72.96&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Destination port: [80]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Specify source? [n]:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Repeat count: [5]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Timeout in seconds: [2]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No source specified. Pinging from identity interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sending 5 TCP SYN requests to 192.168.72.96 port 80&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;from 10.164.95.98, timeout is 2 seconds:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!!!!!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 91/95/107 ms&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Failed on 9.6:-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TCP Ping [n]: y&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Interface: ASSOCIATES_VLAN300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Target IP address: 192.168.72.96&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Destination port: [80]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Specify source? [n]:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Repeat count: [5]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Timeout in seconds: [2]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No source specified. Pinging from identity interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sending 5 TCP SYN requests to 192.168.72.96 port 80&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;from 10.164.115.98, timeout is 2 seconds:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;?????&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Success rate is 0 percent (0/5)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any Help you can&amp;nbsp;give to diagnose this issue is&amp;nbsp;greatly&amp;nbsp;received.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:35:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959251#M144618</guid>
      <dc:creator>Chris Bloy</dc:creator>
      <dc:date>2019-03-12T08:35:18Z</dc:date>
    </item>
    <item>
      <title>ICMP traffic is not inspected</title>
      <link>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959252#M144619</link>
      <description>&lt;P&gt;ICMP traffic is not inspected by the firewall so it's possible that you have ICMP inspection turned on or it's explicitly allowed by an acl&amp;nbsp;in the firewall where you are able to ping and not in the one that where it's failing. Since you didn't share interface configuration I can't tell if you are going from a higher to lower or vice versa.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Firewall where ping is failing:&lt;/P&gt;
&lt;P&gt;show run policy-map (it will show what protocols are being inspected, tcp and udp are inspected by default)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;you can either turn icmp inspection on under the global policy or create a custom class map to only allow specific host.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2016 18:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959252#M144619</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2016-11-25T18:56:47Z</dc:date>
    </item>
    <item>
      <title>Hi Cofee, thank you for the</title>
      <link>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959253#M144620</link>
      <description>&lt;P&gt;Hi Cofee, thank you for the reply, but i already have ICMP inspection enabled, but here is the configuration for the interface:-&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;interface GigabitEthernet1/3.300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;vlan 300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;nameif ASSOCIATES_VLAN300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;security-level 100&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;ip address 10.164.114.1 255.255.255.128&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;interface GigabitEthernet1/6&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;nameif LSP_UPLINK&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;security-level&amp;nbsp;60&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;ip address 10.164.115.98 255.255.255.248&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I really have spent day trying to troubleshoot this and have even thought it was a MPLS fault?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks, Chris&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2016 19:16:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959253#M144620</guid>
      <dc:creator>Chris Bloy</dc:creator>
      <dc:date>2016-11-25T19:16:40Z</dc:date>
    </item>
    <item>
      <title>Since  you have already spent</title>
      <link>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959254#M144621</link>
      <description>&lt;P&gt;Since&amp;nbsp; you have already spent this much troubleshooting I am sure you must have tried debugging icmp packets on the local firewall and if you have access to the remote server or the remote firewall did you check if packets are making to the remote firewall/server? if so what do the logs say.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2016 19:34:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959254#M144621</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2016-11-25T19:34:45Z</dc:date>
    </item>
    <item>
      <title>I have run a capture with</title>
      <link>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959255#M144622</link>
      <description>&lt;P&gt;I have run a capture with icmp and https requests based on source of any and destination 192.167.72.96 is the server that the other properties can access. I don't see any traffic exiting the interface to that subnet, but I do on all other subnet.&lt;/P&gt;
&lt;P&gt;We don't have access to the destination server or wan as it's run by Verizon, so can only see traffic locally. If i run the show route 192.168.72.96 it correct identifies the static route.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Really appreciate your time and help, but I am beginning to believe it's a software version issue?&lt;/P&gt;
&lt;P&gt;we would have to take the site down to prove it with the same release, but it's only this one route that's causing me a headache and it's the finance department!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2016 19:52:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959255#M144622</guid>
      <dc:creator>Chris Bloy</dc:creator>
      <dc:date>2016-11-25T19:52:34Z</dc:date>
    </item>
    <item>
      <title>Yeah I think if it's possible</title>
      <link>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959256#M144624</link>
      <description>&lt;P&gt;Yeah I think if it's possible to downgrade the new 5560x with &lt;SPAN&gt;9.5(2) and have the same running configuration will prove your point.&amp;nbsp;If you a chance let me know the outcome, I would like to know.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2016 19:59:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-says-allowed-but-traffic-doesn-t-pass-help/m-p/2959256#M144624</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2016-11-25T19:59:46Z</dc:date>
    </item>
  </channel>
</rss>

