cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
411
Views
0
Helpful
6
Replies

ASA Firewall

rajeshcv49
Level 1
Level 1

Hi All,

ASA Firewall Packet flow,

source address 10.1.1.1 destnation address 192.168.1.1, In firewall acl entry i allowed icmp for 10.1.1.1 to 192.168.1.1, but in global-policy if i drop the icmp packets. Can ping 10.1.1.1 to 192.168.1.1?

6 Replies 6

Collin Clark
VIP Alumni
VIP Alumni

You can configure global access rules in conjunction with interface access rules, in which case, the specific interface access rules are always processed before the general global access rules.

If a packet is permitted in the specific interface rule, but denied in the global policy, will the packet be permitted or denied?

CF

Hi,

As Collin said, it always look for the interface access list first and then only it will look for the global.

So ideally the interface access list should allow the traffic if it matches.

Thanks,

Shivapramod M

So anything that is permitted in the interface access-list will not be checked against the global policy. Am I right?

CF

Yes, Your right

Thank you Collin Clark.

Review Cisco Networking for a $25 gift card