ASA Transparent Firewall Behavior
I posted a couple of questions to Twitter this morning as both a challenge and a learning experience for myself and others. These two questions were as follows: How does the ASA in transparent mode know which interface remote networks should be reached through?What is permitted at layer 2 disregarding- layer 3 restrictions? In addition, I’d like to pose one more question: In what case does the ASA in Transparent mode drop the first packet? I promised an answer, but Twitter just didn’t allow enough characters to describe the behavior well....
Traceroute Through the ASA
The Cisco ASA has some interesting characteristics when dealing with traceroute. With most traffic, including ICMP echo, outbound traffic can be inspected to allow the incoming traffic associated with the same flow. Inspecting “ICMP” or even “ICMP Error” does not result in traceroute functioning through the ASA.
Not enough data.
Calculated for blogs with 20+ followers.
- Sana Aijazi
security, defence, pakistan
- Cisco Network Engineer
ccie, cisco, ip
- Go4HaKING
Pc tips tricks, security, utilities
- View From The Edge
Technology, Security, Golf
- Mashable
technology, startups, social networks
Questions? contact: networkedblogs@ninua.com
Copyright (C) 2008, Ninua, Inc.