cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
263
Views
1
Helpful
2
Replies

Cisco ASA ACL inspection

MBestt
Level 1
Level 1

Hello,

 

I have a question about how a Cisco ASA inspects traffic and hits on an ACL? Does it perform scans from top to bottom, or does it select the best match based on the specific traffic passing the firewall?

 

Thanks,

MB

1 Accepted Solution

Accepted Solutions

@MBestt top to bottom in order.

"An ACL is made up of one or more ACEs. Unless you explicitly insert an ACE at a given line, each ACE that you enter for a given ACL name is appended to the end of the ACL. The order of ACEs is important. When the ASA decides whether to forward or drop a packet, the ASA tests the packet against each ACE in the order in which the entries are listed. After a match is found, no more ACEs are checked."

https://www.cisco.com/c/en/us/td/docs/security/asa/asa920/configuration/firewall/asa-920-firewall-config/access-acls.html

 

View solution in original post

2 Replies 2

@MBestt top to bottom in order.

"An ACL is made up of one or more ACEs. Unless you explicitly insert an ACE at a given line, each ACE that you enter for a given ACL name is appended to the end of the ACL. The order of ACEs is important. When the ASA decides whether to forward or drop a packet, the ASA tests the packet against each ACE in the order in which the entries are listed. After a match is found, no more ACEs are checked."

https://www.cisco.com/c/en/us/td/docs/security/asa/asa920/configuration/firewall/asa-920-firewall-config/access-acls.html

 

Can I ask why you interested in order or acl?

MHM

Review Cisco Networking for a $25 gift card