cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1355
Views
0
Helpful
2
Replies

ASA access-group question

networkadmin411
Level 1
Level 1

If a firewall is configured with a global access-group and an interface in access-group, what the order that access-lists would be processed?

1 Accepted Solution

Accepted Solutions

Hi,
An ACL applied to an interface is processed before the global ACL.

Usually I find most organisations don't use a global ACL, just an interface ACLs.

FYI, a control-plane ACL is applied before an interface ACL, but the control-plane only processes traffic destined to the ASA itself, where as the interface/global ACL processes traffic through the ASA.

HTH

View solution in original post

2 Replies 2

Hi,
An ACL applied to an interface is processed before the global ACL.

Usually I find most organisations don't use a global ACL, just an interface ACLs.

FYI, a control-plane ACL is applied before an interface ACL, but the control-plane only processes traffic destined to the ASA itself, where as the interface/global ACL processes traffic through the ASA.

HTH

This matches what I thought. I am in the process of migrating multiple firewalls away from global ACLs and wanted to be sure that I was on the right path. Thank you.
Review Cisco Networking for a $25 gift card