cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
471
Views
15
Helpful
2
Replies

ASA 5525 ACL traffic behavior...

Hello.

I am unclear on ASA 5525 ACL traffic behavior...

If an ACL is implemented on an interface in one direction, are packets within this session that have been permitted by that ACL automatically allowed back in from the other side during that same session?

In other words-- Is it true that ASA ACLs are inherently bi-directional if the initiator of the communication was permitted through the firewall?

Thank you.

Thank you.

2 Accepted Solutions

Accepted Solutions

@jmaxwellUSAF yes, the ASA is a stateful firewall, so return traffic is permitted automatically.

View solution in original post

If an ACL is implemented on an interface in one direction, are packets within this session that have been permitted by that ACL automatically allowed back in from the other side during that same session? Yes

the traffic initiate from one interface, it check by ACL apply IN to that interface, and then the traffic will build Conn in ASA, 
this Conn will use for return back traffic. 



View solution in original post

2 Replies 2

@jmaxwellUSAF yes, the ASA is a stateful firewall, so return traffic is permitted automatically.

If an ACL is implemented on an interface in one direction, are packets within this session that have been permitted by that ACL automatically allowed back in from the other side during that same session? Yes

the traffic initiate from one interface, it check by ACL apply IN to that interface, and then the traffic will build Conn in ASA, 
this Conn will use for return back traffic. 



Review Cisco Networking for a $25 gift card