06-29-2018 07:52 AM - edited 03-11-2019 01:44 AM
Hi all,
to my knowledge, SGACLs are normally statless, which means that I have to explictly allow return traffic in cases where SGACLs are used.
Are there any devices (besides ASA/FTD) which are stateful when using SGACLs?
Roland
Solved! Go to Solution.
06-29-2018 08:22 AM
Hi Roland,
all devices downloading SGACLs from ISE are stateless (switches, routers, AP's via WLC).
As you say, firewalls offer stateful inspection but they use SGFW rules, they don't download SGACLs from ISE.
Routers can offer stateful operation while using SGT's in zone based firewall setup but again, SGACLs are not downloaded for this function.
06-29-2018 08:22 AM
Hi Roland,
all devices downloading SGACLs from ISE are stateless (switches, routers, AP's via WLC).
As you say, firewalls offer stateful inspection but they use SGFW rules, they don't download SGACLs from ISE.
Routers can offer stateful operation while using SGT's in zone based firewall setup but again, SGACLs are not downloaded for this function.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide