cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
789
Views
0
Helpful
2
Replies

SGACLs and Security Group Tagging Stateful or Stateless

gtuthill
Level 1
Level 1

Could any one please confirm my following assumptions about the processing of SGACLs.

a) SGACLs on a ASA firewall are stateful and processed as normal ACL's on a per interface basis ?

b) SGACLs on IOS are processed  after normal  Ingress ACL'a and before Egress ACL's and are stateless ?

Thanks in advance.

2 Replies 2

jan.nielsen
Level 7
Level 7

a) Yes, the ASA does not download ACLs from ISE as a swith does, it just uses SGT's in it's regular interface based ACLs, so you can use interface and global acls like normal.

b) Yes, that is also my understanding

Hi Ian,

Many thanks for taking the time to reply/

Much appreciated.

Graham.