cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
533
Views
0
Helpful
1
Replies

What needs to be done to redirect traffic to ASA SFR Module in Inline mode

subrun.jamil
Beginner
Beginner

I have my Any Connect VPN and Site to Site VPN Traffic redirected to SFR module while configuring almost similar to below rule. Difference is in my box I have configured the traffic here what I mentioned as XXXX. 

 

ciscoasa(config)# access-list sfr_redirect extended permit ip XXXX XXXX
ciscoasa(config)# class-map sfr
ciscoasa(config-cmap)# match access-list sfr_redirect
ciscoasa(config-pmap-c)# sfr fail-open monitor-only

 

Now I need to configure this as an Inline Mode to start Inspecting the traffic. What are the steps I need to do to accomplish this other than configuring below command 

 

ciscoasa(config-pmap-c)# sfr fail-open

1 Reply 1

Mohammed al Baqari
VIP Advisor VIP Advisor
VIP Advisor
that is correct. This will start inspecting the traffic assuming that you
have inspection rule is configure in SFR.
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers