cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1279
Views
0
Helpful
2
Replies

ASA Packet Tracer

siclines1234
Level 1
Level 1

Whenever I use the Packet Tracer in ASDM, I receive Flow is denied by configured rule. But I have rules that allow traffic to go from src - any and any - dst

Why would it do that?

2 Replies 2

edadios
Cisco Employee
Cisco Employee

Configured rule include inspections, rpf, and other firewall security function (like accelerated security path).

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s2.html#wp1351326

It will be good to look at the overall steps the traffic flow took, and from there, kind of determine, which step previous or  next, that may have contributed to the packet being deny.

You may have configured acl to allow source to a destination, but then, the flow may take a different path, due to a misconfigured/conflicted NAT, and result in the deny of the flow.

Regards,

The ASA packet tracer is a nice feature, but syslog is a much better diagnostic tool in determining what is preventing functionally.

Chris

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: