cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
577
Views
0
Helpful
1
Replies

What needs to be done to redirect traffic to ASA SFR Module in Inline mode

subrun.jamil
Level 1
Level 1

I have my Any Connect VPN and Site to Site VPN Traffic redirected to SFR module while configuring almost similar to below rule. Difference is in my box I have configured the traffic here what I mentioned as XXXX. 

 

ciscoasa(config)# access-list sfr_redirect extended permit ip XXXX XXXX
ciscoasa(config)# class-map sfr
ciscoasa(config-cmap)# match access-list sfr_redirect
ciscoasa(config-pmap-c)# sfr fail-open monitor-only

 

Now I need to configure this as an Inline Mode to start Inspecting the traffic. What are the steps I need to do to accomplish this other than configuring below command 

 

ciscoasa(config-pmap-c)# sfr fail-open

1 Reply 1

that is correct. This will start inspecting the traffic assuming that you
have inspection rule is configure in SFR.
Review Cisco Networking products for a $25 gift card