<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SFR access control policy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sfr-access-control-policy/m-p/3375841#M923965</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share the actual rules screenshot?&lt;/P&gt;
&lt;P&gt;Or may be do system support firewall-engine debug or system support trace (if above 6.2) and check how the traffic is matched against the rules. That would give us some more idea on whats happening.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 May 2018 07:36:24 GMT</pubDate>
    <dc:creator>yogdhanu</dc:creator>
    <dc:date>2018-05-01T07:36:24Z</dc:date>
    <item>
      <title>SFR access control policy</title>
      <link>https://community.cisco.com/t5/network-security/sfr-access-control-policy/m-p/3375133#M923962</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;you may be thinking what I am speaking is not&amp;nbsp;logic but it is happening with me&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problems:&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;have exempted certain mangers from restrictions&amp;nbsp; and they&amp;nbsp;are hitting to&amp;nbsp;the proper policy and things are working fine, as soon as I make a&amp;nbsp;additional policy for deny any any from inside to outside zone&amp;nbsp;, managers and users traffic starts hitting the deny policy and things get blocked,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please find the attached error&amp;nbsp;is it this&amp;nbsp;error is&amp;nbsp;making a problem.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-access-control-policy/m-p/3375133#M923962</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2020-02-21T15:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: SFR access control policy</title>
      <link>https://community.cisco.com/t5/network-security/sfr-access-control-policy/m-p/3375249#M923963</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error screenshot and problem seems not connected.&lt;/P&gt;
&lt;P&gt;The error that you get may be because a Realm for which some user based rules were created are there in the access control policy but the realm is already deleted.&lt;/P&gt;
&lt;P&gt;You would need to delete the reference user based rules from ACP which point to deleted realm.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I assume with this error, you cannot deploy policy. With that, creating a deny rule should not affect anyone because the rules are not deployed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May be I didn't get the problem right.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 08:04:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-access-control-policy/m-p/3375249#M923963</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-04-30T08:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: SFR access control policy</title>
      <link>https://community.cisco.com/t5/network-security/sfr-access-control-policy/m-p/3375589#M923964</link>
      <description>&lt;P&gt;Dear Yogdhanu,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the rules get deployed and they become active even by the hit counts this means the error is not affecting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have only one relam and no such user groups are deleted on daily basis hence I was mentioning the managers rule&amp;nbsp; in which I am calling the managers their group has not changed from many years&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 19:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-access-control-policy/m-p/3375589#M923964</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-04-30T19:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: SFR access control policy</title>
      <link>https://community.cisco.com/t5/network-security/sfr-access-control-policy/m-p/3375841#M923965</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share the actual rules screenshot?&lt;/P&gt;
&lt;P&gt;Or may be do system support firewall-engine debug or system support trace (if above 6.2) and check how the traffic is matched against the rules. That would give us some more idea on whats happening.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 07:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-access-control-policy/m-p/3375841#M923965</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-05-01T07:36:24Z</dc:date>
    </item>
  </channel>
</rss>

