<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A question about ASA 8.3 global ACLs against interface ACLs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/a-question-about-asa-8-3-global-acls-against-interface-acls/m-p/1479237#M740063</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It matches interface acl first before global.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the documentation for your reference :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/access_rules.html#wp1083595"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/access_rules.html#wp1083595&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;####&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;You can configure global access rules in&amp;nbsp; conjunction with interface access rules, in which case, the specific&amp;nbsp; interface access rules are always processed before the general global&amp;nbsp; access rules. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;####&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Jun 2010 13:03:28 GMT</pubDate>
    <dc:creator>edadios</dc:creator>
    <dc:date>2010-06-10T13:03:28Z</dc:date>
    <item>
      <title>A question about ASA 8.3 global ACLs against interface ACLs</title>
      <link>https://community.cisco.com/t5/network-security/a-question-about-asa-8-3-global-acls-against-interface-acls/m-p/1479236#M740041</link>
      <description>&lt;P&gt;Hello Cisco Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question about the Global ACLs feature introduced in ASA 8.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which ACLs are match first, Global ACLs or the regular interface-base ACLs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I understood, if both Blobal and interface-base ACLs exist in the policy, the firewall will try to match (incoming/outgoing) traffic against the interface-base ACLs and if no match is found then the firewall tries&amp;nbsp; to match the traffic against the Blobal ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is that correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-question-about-asa-8-3-global-acls-against-interface-acls/m-p/1479236#M740041</guid>
      <dc:creator>shaijosef</dc:creator>
      <dc:date>2019-03-11T17:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: A question about ASA 8.3 global ACLs against interface ACLs</title>
      <link>https://community.cisco.com/t5/network-security/a-question-about-asa-8-3-global-acls-against-interface-acls/m-p/1479237#M740063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It matches interface acl first before global.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the documentation for your reference :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/access_rules.html#wp1083595"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/access_rules.html#wp1083595&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;####&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;You can configure global access rules in&amp;nbsp; conjunction with interface access rules, in which case, the specific&amp;nbsp; interface access rules are always processed before the general global&amp;nbsp; access rules. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;####&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 13:03:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-question-about-asa-8-3-global-acls-against-interface-acls/m-p/1479237#M740063</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2010-06-10T13:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: A question about ASA 8.3 global ACLs against interface ACLs</title>
      <link>https://community.cisco.com/t5/network-security/a-question-about-asa-8-3-global-acls-against-interface-acls/m-p/1479238#M740090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 13:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-question-about-asa-8-3-global-acls-against-interface-acls/m-p/1479238#M740090</guid>
      <dc:creator>shaijosef</dc:creator>
      <dc:date>2010-06-10T13:47:53Z</dc:date>
    </item>
  </channel>
</rss>

