cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2410
Views
0
Helpful
2
Replies

ASA 9.1 Packet Flow Query

Hi All,

I have Cisco ASA firewall running 9.1 ios, with IPSec tunnel terminated on Outside interface which is up, the interesting traffic from other side peer is sourced with 192.168.10.2 to destination 172.16.10.2,  And the ip 172.16.10.2 is Static NAT with 10.10.10.2 (Outside to Inside interfaces) at my End.

So Can some body Please explain me below points in this scenario.

1. what is Order of operation or Packet Flow for ASA 9.1 on outside interface with IPSec tunnel terminated on it.

2. Should my Access list on outside interface be with source 192.168.10.2 to Destination 10.10.10.2 ? , if i want to apply a filter.

Thanks in Advance.

 Ali.

2 Replies 2

jj27
Spotlight
Spotlight

Your ACL should reference the real private IP address as the destination because NAT is processed before ACLs.  

Thanks ,

could you brief me with packet flow list for 9.1 ios on outside interface with IPsec.