cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
935
Views
0
Helpful
2
Replies

Deny in firewall

grapevine
Level 5
Level 5
Why do we write a 'deny' statement in the firewall, when there is always an 'implicit deny' at the end of the access list
2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

An explicit deny allows one to generate log messages for the packets that are denied.

Some organizations use those for analysis and/or blacklisting / shunning of the source IPs.

The other reason I have seen cited is that it keeps some auditors happier to see the explicit denies. 🙂

 

johnlloyd_13
Level 11
Level 11

further adding to marvin's post, we put an explicit deny (on 'outside' interface) in order to customize the logging level and interval of syslog message 106100.

http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4769049

Review Cisco Networking for a $25 gift card