cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1608
Views
5
Helpful
7
Replies

ASA Firewall error while adding SCTP in ACCESS LIST

HARIS_HUSSAIN
VIP Alumni
VIP Alumni

In ASA When i Try to add the SCTP protocol  the ASDM give below error.Can any one help here to understand SCTP Options in ASA & why does it now work ?

SCTP-PROTOCOL-1.PNG

 

 SCTP-ERROR-2.PNG

7 Replies 7

Sheraz.Salim
VIP Alumni
VIP Alumni

you need to define a host/object network/object-group

 

for example.

 

access-list inside_in extended permit sctp any host 192.168.x.x

yo can not have access-list inside_in extended permit sctp any any

please do not forget to rate.

I tried with SCTP command but ASA is unable to identify SCTP Protocol.


ciscoasa(config)# access-l TEST-1 ext permit sctp any host 192.168.10.1
^
ERROR: % Invalid input detected at '^' marker.
ciscoasa(config)# access-l TEST-1 ext permit s?

configure mode commands/options:
snp
ciscoasa(config)# access-l TEST-1 ext permit sctp ?
ERROR: % Unrecognized command
ciscoasa(config)# access-l TEST-1 ext permit sctp

what ASA version you running on ?

i test this command on 9.8 and it working.

please do not forget to rate.

It looks like SCTP protocol support was add in ASA v9.5, release notes.

 

As has Radio_City, I've confirmed it works on my image (9.9)

 

HTH

 

Mine i s Software Version 9.1

What hardware are you running? If it's too old (5505, 5510, 5520 etc) it may not support the newer firmware versions.

just to add what RJI asid

 

check this matrix of software in regards to firewall hardware

https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#id_59423

please do not forget to rate.
Review Cisco Networking for a $25 gift card