cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2104
Views
0
Helpful
3
Replies

ACL or Routing first

mahesh18
Level 6
Level 6

 

Hi everyone,

 

I am trying to check routing for traffic flow from source to destination.

When traffic is hitting  the firewall say interface inside then i do sh run route

i noticed firewall has no static route to destination subnet.

So in this case will firewall create any log message?

 

So need to know when traffic is coming from inside interface of firewall and say it has to go to destination subnet 10.10.10.1 on port 445 and there is

no routing in place for 10.10.10.1 Will firewall check routing first or ACL?

 

Regards

Mahesh

2 Accepted Solutions

Accepted Solutions

 

Hi

I think this document may answer your question 

http://www.cisco.com/image/gif/paws/113396/asa-packet-flow-00.pdf

View solution in original post

The ASA firewall will first check to see if there already is a connection for the traffic in the state table, If there is no existing connection it will then check the ACL, then routing table.

If you want to see the packet flow through the ASA you could do a packet-tracer which will show you exactly the flow of a packet...with the exception of the checking the state table.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

3 Replies 3

 

Hi

I think this document may answer your question 

http://www.cisco.com/image/gif/paws/113396/asa-packet-flow-00.pdf

Many thanks

Regards

Mahesh

The ASA firewall will first check to see if there already is a connection for the traffic in the state table, If there is no existing connection it will then check the ACL, then routing table.

If you want to see the packet flow through the ASA you could do a packet-tracer which will show you exactly the flow of a packet...with the exception of the checking the state table.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card