<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,I think if you would like in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694780#M194526</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think if you would like to verify traffic drops from large ACE , I think packet tracer would be the best option.&lt;/P&gt;&lt;P&gt;Running packet Tracer for that specific traffic would help you verify the traffic being passed or dropped.&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/29601/troubleshooting-access-problems-using-packet-tracer&lt;/P&gt;&lt;P&gt;Also , using the Syslog ID:- 106023&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logmsgs1.html#pgfId-6482625&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
    <pubDate>Mon, 04 May 2015 11:45:57 GMT</pubDate>
    <dc:creator>Vibhor Amrodia</dc:creator>
    <dc:date>2015-05-04T11:45:57Z</dc:date>
    <item>
      <title>how to fastly troubleshooting which access list rule drop specific traffic</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694779#M194525</link>
      <description>&lt;P&gt;how to fastly troubleshooting which access list rule drop specific traffic&amp;nbsp;from ten thousands of rules?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694779#M194525</guid>
      <dc:creator>martlee2</dc:creator>
      <dc:date>2019-03-26T00:55:47Z</dc:date>
    </item>
    <item>
      <title>Hi,I think if you would like</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694780#M194526</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think if you would like to verify traffic drops from large ACE , I think packet tracer would be the best option.&lt;/P&gt;&lt;P&gt;Running packet Tracer for that specific traffic would help you verify the traffic being passed or dropped.&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/29601/troubleshooting-access-problems-using-packet-tracer&lt;/P&gt;&lt;P&gt;Also , using the Syslog ID:- 106023&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logmsgs1.html#pgfId-6482625&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 11:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694780#M194526</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T11:45:57Z</dc:date>
    </item>
    <item>
      <title>I have used packet tracer but</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694781#M194527</link>
      <description>&lt;P&gt;I have used packet tracer but config attribute is empty&lt;/P&gt;&lt;P&gt;how to show the config of access rule in config attribute of packet tracer?&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 11:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694781#M194527</guid>
      <dc:creator>martlee2</dc:creator>
      <dc:date>2015-05-04T11:48:47Z</dc:date>
    </item>
    <item>
      <title>Hi,use the "detail" keyword</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694782#M194528</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;use the "detail" keyword at the end of the packet tracer command:-&lt;/P&gt;&lt;P&gt;packet-tracer input outside tcp&amp;nbsp; 10.190.2.156 3456 10.190.32.45 22 &lt;STRONG&gt;detail&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 11:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694782#M194528</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T11:51:18Z</dc:date>
    </item>
    <item>
      <title>packet tracer command i tried</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694783#M194529</link>
      <description>&lt;P&gt;packet tracer command i tried already had detail option at the end&lt;/P&gt;&lt;P&gt;still do not have config in config attribute&lt;/P&gt;&lt;P&gt;is there a command to enable show config in config attribute in packet tracer?&lt;/P&gt;&lt;P&gt;if so, it is default disabled shown config in packet tracer?&lt;/P&gt;&lt;P&gt;why disable shown?&lt;/P&gt;&lt;P&gt;is there security reason about this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if it is due to rules not exist to allow the traffic, is it the reason?&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 12:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694783#M194529</guid>
      <dc:creator>martlee2</dc:creator>
      <dc:date>2015-05-04T12:15:46Z</dc:date>
    </item>
    <item>
      <title>Hi,If there is configuration</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694784#M194530</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If there is configuration which is dropping traffic it will show up in the output with detailed keyword.&lt;/P&gt;&lt;P&gt;Are you seeing implicit rule dropping the traffic.&lt;/P&gt;&lt;P&gt;Please post the output from the packet tracer.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 12:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694784#M194530</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T12:15:47Z</dc:date>
    </item>
    <item>
      <title>though we already found that</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694785#M194531</link>
      <description>&lt;P&gt;though we already found that is it due to one of rule not include an ip address,&lt;/P&gt;&lt;P&gt;it seems that it can not show some tips about this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i guess that it may be due to the default rule of ASA which drop all when not match&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can we make a conclusion that every time we see config attribute is&lt;/P&gt;&lt;P&gt;empty means one of rules do not allow specific traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Forward Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in &amp;nbsp;id=0x7ffad41dd5a0, priority=11, domain=permit, deny=true&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hits=873597888, user_data=0x5, cs_id=0x0, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; src ip/id=0.0.0.0, mask=0.0.0.0, port=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 12:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694785#M194531</guid>
      <dc:creator>martlee2</dc:creator>
      <dc:date>2015-05-04T12:21:25Z</dc:date>
    </item>
    <item>
      <title>Hi,As this traffic seems to</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694786#M194532</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;As this traffic seems to be from outside to inside , I think this has to be with the incorrect NAT rule as you pointed out.&lt;/P&gt;&lt;P&gt;Now , this Implicit rule drop is in cases when either we use the source or destination as ASA interfaces itself.&lt;/P&gt;&lt;P&gt;In some case when the NAT phase is not hit , this will be the default drop reason.&lt;/P&gt;&lt;P&gt;These cannot be checked as this is traffic not being denied by the access group on the interface but incorrect or missing some configuration.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 12:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694786#M194532</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T12:21:26Z</dc:date>
    </item>
    <item>
      <title>can we make a conclusion that</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694787#M194533</link>
      <description>&lt;P&gt;can we make a conclusion that every time we see config attribute is&lt;/P&gt;&lt;P&gt;empty means one of rules do not allow specific traffic?&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 12:25:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694787#M194533</guid>
      <dc:creator>martlee2</dc:creator>
      <dc:date>2015-05-04T12:25:13Z</dc:date>
    </item>
    <item>
      <title>Hi,Yes , we can make this</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694788#M194534</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes , we can make this conclusion as at the end of every access group there would be an implicit deny rule.&lt;/P&gt;&lt;P&gt;Also , there can be times when an incorrect packet tracer might also give this same drop.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 12:39:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fastly-troubleshooting-which-access-list-rule-drop/m-p/2694788#M194534</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T12:39:06Z</dc:date>
    </item>
  </channel>
</rss>

