cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9627
Views
0
Helpful
4
Replies

ASA rule check

CCOCNSC21
Level 1
Level 1

Hi All,

 

Before applying any new firewall rule (source, destination, port) is there any way , i mean a show command in ASA to check whether rule is already permitted or denied by ACL ?

 

Regards,

Muhammed

1 Accepted Solution

Accepted Solutions

Francesco Molino
VIP Alumni
VIP Alumni
Hi

There's no tool for that, however you can use packet-tracer embedded in asa to test a traffic and if this traffic is allowed you'll see a success result if not allowed you'll get a fail status. This way you'll be able to see if your acl needs to be created or not.


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

View solution in original post

4 Replies 4

Francesco Molino
VIP Alumni
VIP Alumni
Hi

There's no tool for that, however you can use packet-tracer embedded in asa to test a traffic and if this traffic is allowed you'll see a success result if not allowed you'll get a fail status. This way you'll be able to see if your acl needs to be created or not.


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Another way is to use show access-l x.x.x.x

Put an IP from the source or destination object and you will see what rule
is matching

Hi,



"Sh access-list XXXXX" syntax didn't work. Best way I believe doing via the packet tracer syntax.


cisco IOS access-list verification tool
https://aclcheck.ru
Review Cisco Networking products for a $25 gift card