cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9109
Views
0
Helpful
1
Replies

Control plane ACL on ASA

krishnadig
Level 1
Level 1

Hi!

On ASA, suppose I apply a inbound control plane ACL on outside interface; what will be the impact / consequence to the inbound traffic that is using outside interface IP for PAT or Static PAT.

Control plan ACL is applied to restrict to-the-box traffic.

Thanks in advance

Krishna

1 Reply 1

nspasov
Cisco Employee
Cisco Employee

Hello Krishna-

Take a look at the link below that I think will help you configure control-plane based ACL for your Firewall:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa95/configuration/firewall/asa-95-firewall-config/access-rules.html

So by adding the control-plane keyword to the ACL entry, the traffic inspection applies to traffic destined to the ASA. Without the control-plane keyword, the ACL entries will apply to traffic traversing through the ASA.

Also, keep in mind that ASA based control-plane ACLs (telnet, ssh, http, etc) will override the control-plane ACL applied on the interface. 

I hope this helps!

Thank you for rating helpful posts!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card