Cisco ASA ACL applied to global

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Cisco ASA ACL applied to global

L3 Networker

I am migrating a Cisco ASA config that has an ACL that is applied to global (access-group CSM_FW_ACL_ in interface if_global) as opposed to an interface. I believe I understand how this is applied in the ASA but noticed that Expedition did nothing with the ACL as far as I can tell. Is there a way to handle this in Expedition to make it work? If not does anyone no another way to convert this ACL outside of Expedition? It is an extremely large ACL, otherwise I would just do it by hand.

 

Thanks.

2 REPLIES 2

L3 Networker

HI,

 

we like to get more information about your Cisco ASA configuration and version you are figuring out this issue.
Can you please get in touch with us via fwmigrate@paloaltonetworks.com or send me a private message here?

 

regards

Sven Waschkut
Solution Engineer, Expedition

Actually it turns out the config did get migrated correctly. It appears that the ACL entries for the global access-group get distributed to zones based on routes which I did not realize at first.

 

Thanks for the quick response.

  • 3072 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!