cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
292
Views
0
Helpful
2
Replies

Cisco ASA Packet Flow Information

Hello,

I have a firewall rule( ACL) that allows connection between source 1.1.1.1 and destination 2.2.2.2 on any port.

access-list outbound extended permit ip host 1.1.1.1 host 2.2.2.2

Question:

If I remove above rule and add it back again(~after 1 min), will the above connection still works? In other words, How long will the above connection work after I remove acl?

Really appreciate your response.

Thanks,

Ashish

2 Replies 2

Philip D'Ath
VIP Alumni
VIP Alumni

I think it will stop working immediately.

Antoine Leblond
Level 1
Level 1

As far as I know, if it's a TCP connection, current established connections will remain up until they end or timeout, removing the acl will not kill them.

You will have to "clear conn" them to forcibly shut them out, then they will be denied until you re-add the acl.

Review Cisco Networking for a $25 gift card