Cisco ASA ACL applied to global

Reply
L2 Linker

Cisco ASA ACL applied to global

I am migrating a Cisco ASA config that has an ACL that is applied to global (access-group CSM_FW_ACL_ in interface if_global) as opposed to an interface. I believe I understand how this is applied in the ASA but noticed that Expedition did nothing with the ACL as far as I can tell. Is there a way to handle this in Expedition to make it work? If not does anyone no another way to convert this ACL outside of Expedition? It is an extremely large ACL, otherwise I would just do it by hand.

 

Thanks.

L2 Linker

Re: Cisco ASA ACL applied to global

HI,

 

we like to get more information about your Cisco ASA configuration and version you are figuring out this issue.
Can you please get in touch with us via fwmigrate@paloaltonetworks.com or send me a private message here?

 

regards

Sven Waschkut
Solution Engineer, Expedition

L2 Linker

Re: Cisco ASA ACL applied to global

Actually it turns out the config did get migrated correctly. It appears that the ACL entries for the global access-group get distributed to zones based on routes which I did not realize at first.

 

Thanks for the quick response.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!