<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA access-group question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-access-group-question/m-p/4000813#M30754</link>
    <description>Hi,&lt;BR /&gt;An ACL applied to an interface is processed before the global ACL.&lt;BR /&gt;&lt;BR /&gt;Usually I find most organisations don't use a global ACL, just an interface ACLs.&lt;BR /&gt;&lt;BR /&gt;FYI, a control-plane ACL is applied before an interface ACL, but the control-plane only processes traffic destined to the ASA itself, where as the interface/global ACL processes traffic through the ASA.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
    <pubDate>Wed, 18 Dec 2019 18:50:07 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2019-12-18T18:50:07Z</dc:date>
    <item>
      <title>ASA access-group question</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-group-question/m-p/4000795#M30753</link>
      <description>&lt;P&gt;If a firewall is configured with a global access-group and an interface in access-group, what the order that access-lists would be processed?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2019 18:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-group-question/m-p/4000795#M30753</guid>
      <dc:creator>networkadmin411</dc:creator>
      <dc:date>2019-12-18T18:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA access-group question</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-group-question/m-p/4000813#M30754</link>
      <description>Hi,&lt;BR /&gt;An ACL applied to an interface is processed before the global ACL.&lt;BR /&gt;&lt;BR /&gt;Usually I find most organisations don't use a global ACL, just an interface ACLs.&lt;BR /&gt;&lt;BR /&gt;FYI, a control-plane ACL is applied before an interface ACL, but the control-plane only processes traffic destined to the ASA itself, where as the interface/global ACL processes traffic through the ASA.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Wed, 18 Dec 2019 18:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-group-question/m-p/4000813#M30754</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-12-18T18:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA access-group question</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-group-question/m-p/4000843#M30755</link>
      <description>This matches what I thought. I am in the process of migrating multiple firewalls away from global ACLs and wanted to be sure that I was on the right path. Thank you.</description>
      <pubDate>Wed, 18 Dec 2019 19:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-group-question/m-p/4000843#M30755</guid>
      <dc:creator>networkadmin411</dc:creator>
      <dc:date>2019-12-18T19:39:49Z</dc:date>
    </item>
  </channel>
</rss>

