cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
480
Views
0
Helpful
1
Replies

Problem with reflexive ACLs

Rob
Level 1
Level 1

Hello,

I've created a reflexive ACL to allow IP SLA flows between two routers.  Looking at the ACL counters, none of the outbound or inbound IP SLA permit statements are incrementing.  Looking at the logs, I can see that my IP SLA return traffic is being blocked by the inbound ACL (I created a "deny ip any any log" at the end of my inbound ACL).  Since the outbound reflexive statements aren't handling the outbound traffic (the counters aren't incrementing), the inbound reflexive ACL statements aren't being built.  When I remove the ACLs, the IP SLA traffic flows normally.

Do ACLs apply to network traffic originated from the router?  If not, how could I build a reflexive ACL to support IP SLA traffic?

Thanks,

Rob

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Robert,

Traffic generated from the routed itself is not taken into consideration for Reflexive ACLs sessions

Looking for some Networking Assistance? 
Contact me directly at jcarvaja@laguiadelnetworking.com

I will fix your problem ASAP.

Cheers,

Julio Carvajal Segura
http://laguiadelnetworking.com

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card