<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Vibhor,As its easier in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716348#M191817</link>
    <description>&lt;P&gt;Thanks Vibhor,&lt;/P&gt;&lt;P&gt;As its easier to work with global acl. do you think interface ACLs may soon be out of use now?&lt;/P&gt;</description>
    <pubDate>Fri, 08 May 2015 13:05:41 GMT</pubDate>
    <dc:creator>ROHIT SHARMA</dc:creator>
    <dc:date>2015-05-08T13:05:41Z</dc:date>
    <item>
      <title>Global ACL vs Interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716345#M191814</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;With the introduction of Global ACL in 8.3 ASA, its like Checkpoint FW now to configure rules.&lt;/P&gt;&lt;P&gt;I have a doubt regarding this.&lt;/P&gt;&lt;P&gt;Is there any disadvantage if i use only global acl in ASA? Functionally it should work fine but not sure about other aspects.&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716345#M191814</guid>
      <dc:creator>ROHIT SHARMA</dc:creator>
      <dc:date>2019-03-12T05:54:14Z</dc:date>
    </item>
    <item>
      <title>Can anyone help me here?</title>
      <link>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716346#M191815</link>
      <description>&lt;P&gt;Can anyone help me here?&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2015 12:53:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716346#M191815</guid>
      <dc:creator>ROHIT SHARMA</dc:creator>
      <dc:date>2015-05-08T12:53:45Z</dc:date>
    </item>
    <item>
      <title>Hi,Global ACL is something</title>
      <link>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716347#M191816</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Global ACL is something which can be used as a rule which might be used to Allow Or Deny traffic if it is not evaluated by the Interface ACL.&lt;/P&gt;&lt;P&gt;I don't see any disadvantage in using this ACL type as it depends on the setup and your requirement.&lt;/P&gt;&lt;P&gt;Most important thing you should note is , it will always be evaluated after the interface ACL.&lt;/P&gt;&lt;P&gt;Also , it centralizes the ACE and is easier to maintain.&lt;/P&gt;&lt;P&gt;Also , check this for some more important usage guidelines:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/configuration/guide/config/access_rules.html#wp1120198&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2015 13:01:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716347#M191816</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-08T13:01:42Z</dc:date>
    </item>
    <item>
      <title>Thanks Vibhor,As its easier</title>
      <link>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716348#M191817</link>
      <description>&lt;P&gt;Thanks Vibhor,&lt;/P&gt;&lt;P&gt;As its easier to work with global acl. do you think interface ACLs may soon be out of use now?&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2015 13:05:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716348#M191817</guid>
      <dc:creator>ROHIT SHARMA</dc:creator>
      <dc:date>2015-05-08T13:05:41Z</dc:date>
    </item>
    <item>
      <title>Hi,I don't think so. As i</title>
      <link>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716349#M191818</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I don't think so. As i pointed out , it depends on the deployment type and requirement and a lot of other factors. The global ACL if very big due to the amount rules can become difficult to manage in large deployments and would be beneficial to separate as per the interfaces.&lt;/P&gt;&lt;P&gt;NAT would also be a big factor in selecting the type of ACL rules.&lt;/P&gt;&lt;P&gt;Also , the priority is also higher than Global ACL.&lt;/P&gt;&lt;P&gt;The Global can only allow/deny inbound traffic. There are some requirements where the outbound traffic needs to be blocked so the interface ACL use is always required.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2015 13:18:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716349#M191818</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-08T13:18:09Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor,</title>
      <link>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716350#M191819</link>
      <description>&lt;P&gt;Hi Vibhor,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;you mentiond that global access rules are applied to traffic that is not avaluated by an interface ACL. What is about ingress traffic, comming through a VPN site to site Tunnel?&lt;/P&gt;
&lt;P&gt;Is this Traffic avaluated by a global access Rule?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;kay&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 13:25:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716350#M191819</guid>
      <dc:creator>k.kroeger</dc:creator>
      <dc:date>2016-01-15T13:25:22Z</dc:date>
    </item>
    <item>
      <title>Global ACL is evaluated only</title>
      <link>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716351#M191820</link>
      <description>&lt;P&gt;Global ACL is evaluated only if there is no matching rule found in Interface ACL. Gloabl ACL is always ingress and traffic coming through a VPN site-site tunnel is not subjected to any ACL.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I hope it helps&lt;/P&gt;
&lt;P&gt;rohit&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2016 06:29:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/2716351#M191820</guid>
      <dc:creator>ROHIT SHARMA</dc:creator>
      <dc:date>2016-01-16T06:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global ACL vs Interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/4902168#M1103328</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The inbound and outbound described here are in terms of the interface. Let's say for example there's an interface gi0/4 named CAT on my ASA FW. The global ACL will only be applicable to the traffic entering through it. So all traffic coming from "CATS" will be checked by this ACL and NOT traffic going to them.&lt;BR /&gt;Please correct me if I am mistaken here.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 10:37:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-acl-vs-interface-acl/m-p/4902168#M1103328</guid>
      <dc:creator>khanzaidsalim</dc:creator>
      <dc:date>2023-08-09T10:37:00Z</dc:date>
    </item>
  </channel>
</rss>

