1377
Views
0
Helpful
2
Replies
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-18-2019 10:25 AM
If a firewall is configured with a global access-group and an interface in access-group, what the order that access-lists would be processed?
Solved! Go to Solution.
Labels:
- Labels:
-
Firewalls
1 Accepted Solution
Accepted Solutions
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-18-2019 10:50 AM
Hi,
An ACL applied to an interface is processed before the global ACL.
Usually I find most organisations don't use a global ACL, just an interface ACLs.
FYI, a control-plane ACL is applied before an interface ACL, but the control-plane only processes traffic destined to the ASA itself, where as the interface/global ACL processes traffic through the ASA.
HTH
An ACL applied to an interface is processed before the global ACL.
Usually I find most organisations don't use a global ACL, just an interface ACLs.
FYI, a control-plane ACL is applied before an interface ACL, but the control-plane only processes traffic destined to the ASA itself, where as the interface/global ACL processes traffic through the ASA.
HTH
2 Replies 2
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-18-2019 10:50 AM
Hi,
An ACL applied to an interface is processed before the global ACL.
Usually I find most organisations don't use a global ACL, just an interface ACLs.
FYI, a control-plane ACL is applied before an interface ACL, but the control-plane only processes traffic destined to the ASA itself, where as the interface/global ACL processes traffic through the ASA.
HTH
An ACL applied to an interface is processed before the global ACL.
Usually I find most organisations don't use a global ACL, just an interface ACLs.
FYI, a control-plane ACL is applied before an interface ACL, but the control-plane only processes traffic destined to the ASA itself, where as the interface/global ACL processes traffic through the ASA.
HTH
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-18-2019 11:39 AM
This matches what I thought. I am in the process of migrating multiple firewalls away from global ACLs and wanted to be sure that I was on the right path. Thank you.
