<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The ASA firewall will first in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-or-routing-first/m-p/2707156#M193913</link>
    <description>&lt;P&gt;The ASA firewall will first check to see if there already is a connection for the traffic in the state table, If there is no existing connection it will then check the ACL, then routing table.&lt;/P&gt;&lt;P&gt;If you want to see the packet flow through the ASA you could do a packet-tracer which will show you exactly the flow of a packet...with the exception of the checking the state table.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Sat, 11 Jul 2015 18:09:41 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2015-07-11T18:09:41Z</dc:date>
    <item>
      <title>ACL or Routing first</title>
      <link>https://community.cisco.com/t5/network-security/acl-or-routing-first/m-p/2707154#M193908</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to check routing for traffic flow from source to destination.&lt;/P&gt;&lt;P&gt;When traffic is hitting &amp;nbsp;the firewall say interface inside then i do sh run route&lt;/P&gt;&lt;P&gt;i noticed firewall has no static route to destination subnet.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;So in this case will firewall create any log message?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;So need to know when traffic is coming from inside interface of firewall and say it has to go to destination subnet 10.10.10.1 on port 445 and there is&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no routing in place for 10.10.10.1 Will firewall check routing first or ACL?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-or-routing-first/m-p/2707154#M193908</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T06:15:05Z</dc:date>
    </item>
    <item>
      <title>Hi MaheshI am very open to</title>
      <link>https://community.cisco.com/t5/network-security/acl-or-routing-first/m-p/2707155#M193910</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I think this document may answer your question&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/image/gif/paws/113396/asa-packet-flow-00.pdf&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2015 21:22:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-or-routing-first/m-p/2707155#M193910</guid>
      <dc:creator>Mark Mc Nicholas</dc:creator>
      <dc:date>2015-07-10T21:22:56Z</dc:date>
    </item>
    <item>
      <title>The ASA firewall will first</title>
      <link>https://community.cisco.com/t5/network-security/acl-or-routing-first/m-p/2707156#M193913</link>
      <description>&lt;P&gt;The ASA firewall will first check to see if there already is a connection for the traffic in the state table, If there is no existing connection it will then check the ACL, then routing table.&lt;/P&gt;&lt;P&gt;If you want to see the packet flow through the ASA you could do a packet-tracer which will show you exactly the flow of a packet...with the exception of the checking the state table.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2015 18:09:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-or-routing-first/m-p/2707156#M193913</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-07-11T18:09:41Z</dc:date>
    </item>
    <item>
      <title>Many thanksRegardsMahesh</title>
      <link>https://community.cisco.com/t5/network-security/acl-or-routing-first/m-p/2707157#M193918</link>
      <description>&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2015 14:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-or-routing-first/m-p/2707157#M193918</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2015-07-13T14:19:35Z</dc:date>
    </item>
  </channel>
</rss>

