cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
368
Views
0
Helpful
2
Replies

8.3 Global Access Policy Question

justintime
Level 1
Level 1

Per the release notes:

If the configuration specifies both a global access policy and interface-specific access policies, the interface-specific policies are evaluated before the global policy.

How does this work with the implicit deny rules on an interface?  I'm assuming that it evalutes all the user-defined access rules on the interface, but doesn't run it through the implicit deny all on the interface, then runs it through the global policy.  If nothing matches in the global scope, then an implicit deny is matched at the end of the global policy - is this correct?

1 Accepted Solution

Accepted Solutions

Panos Kampanakis
Cisco Employee
Cisco Employee

You are correct.

There is not implicit deny on the interface ACL if there is a global ACL defined.

I hope it helps.

PK

View solution in original post

2 Replies 2

Panos Kampanakis
Cisco Employee
Cisco Employee

You are correct.

There is not implicit deny on the interface ACL if there is a global ACL defined.

I hope it helps.

PK

Excellent - my testing looked like that was the case, but I just wanted confirmation.  Thanks so much.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card