05-02-2024 12:46 AM
Hello,
I have a question about how a Cisco ASA inspects traffic and hits on an ACL? Does it perform scans from top to bottom, or does it select the best match based on the specific traffic passing the firewall?
Thanks,
MB
Solved! Go to Solution.
05-02-2024 12:51 AM
@MBestt top to bottom in order.
"An ACL is made up of one or more ACEs. Unless you explicitly insert an ACE at a given line, each ACE that you enter for a given ACL name is appended to the end of the ACL. The order of ACEs is important. When the ASA decides whether to forward or drop a packet, the ASA tests the packet against each ACE in the order in which the entries are listed. After a match is found, no more ACEs are checked."
05-02-2024 12:51 AM
@MBestt top to bottom in order.
"An ACL is made up of one or more ACEs. Unless you explicitly insert an ACE at a given line, each ACE that you enter for a given ACL name is appended to the end of the ACL. The order of ACEs is important. When the ASA decides whether to forward or drop a packet, the ASA tests the packet against each ACE in the order in which the entries are listed. After a match is found, no more ACEs are checked."
05-02-2024 01:00 AM
Can I ask why you interested in order or acl?
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide