ASA5510 v7.0.7 ignoring ACL changes!

Unanswered Question
Jan 26th, 2009

I have made changes to nat and IPSec ACL's but the new lines in the ACL's are being ignored!

This results in packets that should be sent encrypted going out unencrypted even though the packets match the ACL.

On a different interface new rules for nat are not taking effect, thus packets are leaving the ASA without being natted!

Active/Failover in operation.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Ivan Martinon Mon, 01/26/2009 - 08:22

Did you change these Crypto ACl's on the fly? Meaning did you remove crypto map, change settings and reapply the crypto map? If not then you need to bounce the tunnel to make this new changes occur. Were these changes applied on the remote end as well?

Actions

This Discussion