cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5019
Views
3
Helpful
1
Replies

SGACL state-less / stateful?

rmueller@cisco.com
Cisco Employee
Cisco Employee

Hi all,

to my knowledge, SGACLs are normally statless, which means that I have to explictly allow return traffic in cases where SGACLs are used.

Are there any devices (besides ASA/FTD) which are stateful when using SGACLs?

Roland

1 Accepted Solution

Accepted Solutions

jeaves@cisco.com
Cisco Employee
Cisco Employee

Hi Roland,

all devices downloading SGACLs from ISE are stateless (switches, routers, AP's via WLC).

As you say, firewalls offer stateful inspection but they use SGFW rules, they don't download SGACLs from ISE.

Routers can offer stateful operation while using SGT's in zone based firewall setup but again, SGACLs are not downloaded for this function.

View solution in original post

1 Reply 1

jeaves@cisco.com
Cisco Employee
Cisco Employee

Hi Roland,

all devices downloading SGACLs from ISE are stateless (switches, routers, AP's via WLC).

As you say, firewalls offer stateful inspection but they use SGFW rules, they don't download SGACLs from ISE.

Routers can offer stateful operation while using SGT's in zone based firewall setup but again, SGACLs are not downloaded for this function.