cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
804
Views
0
Helpful
1
Replies

Router Acl's & ASA firewall Acl's

Shon
Level 1
Level 1

Hi

As all we know that Acl's are configured in router & firewall.

Acl primary purpose to allow or deny the traffic.

Why we should configure ACL's on ASA firewall. 

1 Reply 1

Greg Smalley
Level 1
Level 1

Firewalls can do much more in controlling traffic versus a typical router.  A basic ASA firewall will be at the very least be a Statefull firewall, which looks for an active session before allow traffic back in the firewall.  This means it is unnecessary to create reflexive rules which may be too broad for traffic coming back to the firewall.  If you are using an ASA as a NSFW (Either FTD or ASA w/Sourcefire) now you can create rules that reference Layer 7 information instead of Layer 4 information.  In short why use a Firewall for ACLs versus a Router?  Because a firewall is much more flexible due to it's statefull firewall nature.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card