10-13-2016 02:22 AM - edited 03-11-2019 12:08 AM
Could any one please confirm my following assumptions about the processing of SGACLs.
a) SGACLs on a ASA firewall are stateful and processed as normal ACL's on a per interface basis ?
b) SGACLs on IOS are processed after normal Ingress ACL'a and before Egress ACL's and are stateless ?
Thanks in advance.
Solved! Go to Solution.
10-14-2016 11:33 AM
a) The ASA Firewall does not use SGACLs. The ASA can however make use of Security Groups and SGT in policies configured at the ASA. This is known as Security Group Firewall. SGACLs are role-based policies with further granularity provided by Access Control Entries within the SGACL. These are configured at ISE and distributed to switches today and other devices such as routers in the very near future. When a policy is created at the ASA (SGFW), they are stateful.
b) SGACLs in IOS are processed at egress. If a standard ACL and an SGACL are both present, the standard ACL is processed first and then the SGACL.
10-14-2016 11:33 AM
a) The ASA Firewall does not use SGACLs. The ASA can however make use of Security Groups and SGT in policies configured at the ASA. This is known as Security Group Firewall. SGACLs are role-based policies with further granularity provided by Access Control Entries within the SGACL. These are configured at ISE and distributed to switches today and other devices such as routers in the very near future. When a policy is created at the ASA (SGFW), they are stateful.
b) SGACLs in IOS are processed at egress. If a standard ACL and an SGACL are both present, the standard ACL is processed first and then the SGACL.
10-14-2016 12:53 PM
Yeah Mike! Thanks for responding to the community question. I was just talking with Kevin R after our team meeting about getting more attention in the community!
Keti
10-14-2016 01:24 PM
Many thanks for your response to my question, very much appreciated..
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide