07-19-2013 05:13 PM - edited 03-11-2019 07:14 PM
Hi Everyone,
Need to confirm if order of ACL marked as red in number 3 is true??
The Cisco ASA security appliance uses the following order to match access rules when only interface ACLs are configured:
The Cisco ASA security appliance uses the following order to match access rules when both interface ACLs and the global ACL are configured:
Regards
Mahesh
Solved! Go to Solution.
07-19-2013 09:15 PM
Hello Mahesh,
In this case we have 2 access-group
One specific (applied to an interface)
One global (applied to all of the interfaces of the ASA)
Which goes first:
The most specific (the one applied to the interface)
If there is no ACL applied to an interface then the less specific takes place (global) and that's it basically,
The implicit deny will be set on both of them.
For Networking Posts check my blog at http://www.laguiadelnetworking.com/category/english/
Cheers,
Julio Carvajal Segura
07-19-2013 10:06 PM
Hello Mahesh,
Here is the thing:
Let me know if you got it,
For Networking Posts check my blog at http://www.laguiadelnetworking.com/category/english/
Cheers,
Julio Carvajal Segura
07-19-2013 09:15 PM
Hello Mahesh,
In this case we have 2 access-group
One specific (applied to an interface)
One global (applied to all of the interfaces of the ASA)
Which goes first:
The most specific (the one applied to the interface)
If there is no ACL applied to an interface then the less specific takes place (global) and that's it basically,
The implicit deny will be set on both of them.
For Networking Posts check my blog at http://www.laguiadelnetworking.com/category/english/
Cheers,
Julio Carvajal Segura
07-19-2013 09:31 PM
Hi Julio,
So does this mean that if Global ACL is applied to ASA then the order will be
1>interface ACL
2>Global ACL
now if we have no match there we know by default it is implicit deny ip any any.
So this implicit will be global or interface ACL?
Regards
MAhesh
07-19-2013 10:06 PM
Hello Mahesh,
Here is the thing:
Let me know if you got it,
For Networking Posts check my blog at http://www.laguiadelnetworking.com/category/english/
Cheers,
Julio Carvajal Segura
07-21-2013 07:55 AM
Hi Julio,
Got it now.
Best regards
Mahesh
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: