cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1165
Views
0
Helpful
5
Replies

Can we specify the source address when using the redirect ACL while posture?

musultan
Cisco Employee
Cisco Employee

Hi,

 

I want to clarify about do we have any caveats when using the source IP/Subnet in the Redirect-ACL when doing posture with ASA or Switch. I didn't find any example out there with source address.

 

Also, comment about the same with DACL ?

5 Replies 5

paul
Advocate
Advocate

For the 2nd question the DACLs are applied to a session.  The switch will automatically substitute in the source IP address.  You shouldn't be specifying the source IP.  I don't thin I have tried using source IPs in posturing rules.  What is your exact use case?

musultan
Cisco Employee
Cisco Employee
My customer would like to specify the source address in the redirect ACL when using with ASA. I was looking for any documentation or wanted to know any caveats related to this.

pan
Cisco Employee
Cisco Employee

How will you know what IP address client is going to get?

What is their reason for asking this? I have many customers that ask for things that don't make sense because they don't understand how thing work. The redirect ACL and DACLs are applied to the user session level. Specifying a source IP makes no sense.


pan
Cisco Employee
Cisco Employee

That's what I wanted to tell we cannot predict what IP address client will get so we cannot have IP specific DACL for posture.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers