12-29-2014 01:38 PM - edited 03-11-2019 10:16 PM
If I have created a MPF service-policy to allow access to certain websites based on REGEX url matchings, and I apply this policy to an ASA interface, what happens if there is an ACL on that same interface and blocks or allows access to certain sites?
Which is processed first? The service policy or the ACL?
What if the ACL blocks bu the service-policy allows?
Solved! Go to Solution.
12-30-2014 09:08 AM
Hi,
Yes , in that case the traffic will be denied after the ASA device inspects the HTTP header.
Thanks and Regards,
Vibhor Amrodia
12-30-2014 02:15 AM
Hi,
ACL is always processes first. The traffic being allowed the by the ACL will only be matched on the service policy.
Refer:-
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113396-asa-packet-flow-00.html
Thanks and Regards,
Vibhor Amrodia
12-30-2014 07:40 AM
Vibhor:
so if a a packet comes in destined for a website address at port 80 and is allowed by the ACL, but the service-policy has a REGEX expression (whitelist/blacklist) that denies access access to that same website, will the connection be terminated?
12-30-2014 09:08 AM
Hi,
Yes , in that case the traffic will be denied after the ASA device inspects the HTTP header.
Thanks and Regards,
Vibhor Amrodia
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide