[c-nsp] Cisco CBAC one stateful rule on an interface bypasses rules on other interfaces
Marco Moock via cisco-nsp <[email protected]> Thu, 11 Dec 2025 19:33:00 +0100
| Newsgroups | gmane.network.nsp.cisco |
|---|---|
| Message-ID | <[email protected]> |
--===============0775384718846712582== Content-Type: multipart/signed; boundary="Sig_/9sjba0zvbRTIsYzqmWjoM2Q"; protocol="application/pgp-signature"; micalg=pgp-sha512 Content-Transfer-Encoding: 7bit --Sig_/9sjba0zvbRTIsYzqmWjoM2Q Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable Hello! I have 2 vlan interfaces with both CBAC (inspect) ACLs. I noticed that in that case the 2nd CBAC ACL (on the outgoing interface) is not being processed, even if it would reject the packet. It is working if traffic goes from an incoming interface without an inspect rule. The ACL on the out interface is being processed in that case. Is that intended behavior, so if one inspect temporary rule exist, the second ACL is bypassed? In case I would like to have inspect rules on both interfaces for traffic to the internet and to have firewalls between the VLANs, what is the preferred way to handle this? interface Vlan5 ipv6 inspect spi-fw-vlan5 in ipv6 traffic-filter vlan5-acl-out out interface Vlan30 ipv6 inspect spi-fw-vlan30 in ipv6 traffic-filter vlan30-acl-out out Both lists have a deny ipv6 any any at the end and the rejects are being logged. If I now try to connect from a machine in VLAN 5 to a machine in 30 to a destination address/port that is should be rejected by vlan30-acl-out, the traffic goes through. If I try to do that from VLAN2 (no ACL attached), the ACL vlan30-acl-out is being processed and the packet will be rejected. --=20 kind regards Marco Send unsolicited bulk mail to [email protected] --Sig_/9sjba0zvbRTIsYzqmWjoM2Q Content-Type: application/pgp-signature Content-Description: Digitale Signatur von OpenPGP Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpXefSZn9R6zNZtTQE76RLz2tRfAFAmk7DlwACgkQE76RLz2t RfBIahAAkq8YZpfbg73sU0wedjJIVehH7RcONoTyTtamWSQjpqMcFhjxCZYtRRqw FRLJ8g/K/VY72RzDXYHfS/W2xf2GeLqZ2iUqloh+7i12Z94QWdYInvYB+0Whuob7 eqaMGVngiGHQo2FMdLT6cOrLQSV8ymocGFaOXFBqv+FN16nj7Itlh7z+grXUCtoT 3iAvidmD8aoQioGtBYH3k57exmQjzCCeZ67PwT5BWAL2OWTD//EPLgk9LWWSzlvY K6tvN3Mx+fWJIpqSUgndqgC5LDklcdxM5MFlkB3rbc5BdEh045lwMeII4+YZJNES l1c5qPpkQBWFc2K/f5MBdPmWD12oBzvsOqbeShH3pobwCbLAudwaowYqr+4voqZZ HpQVI+scH28Y2bmJnWaZacn9wRAbMKj0VcUxpbnspejfguNyc5lb0jfYF/vuydpg 6VwnOAzV5i30ftr0Vyk15HkId6xoD+9XgtSsSp13kAVBRTIQh2mS0/MAPAJfjYBY 6ZiZDRsxDtSiyJmqeRlaLYPACI6OKvny/EewxzxvI0+GKvh/O4FoxIHIIzflf9v1 B/31kguzGhCvFk4F8FNPpuzViU41Wj6L1ePhjG5GzI3zmj3QdCSzRIIz4RH3EMqq ufITjb4OeLqr78E6ud0Mqz2YNzoOh5m+l28IhRF1apQll8LFSfE= =rHdQ -----END PGP SIGNATURE----- --Sig_/9sjba0zvbRTIsYzqmWjoM2Q-- --===============0775384718846712582== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KY2lzY28tbnNw IG1haWxpbmcgbGlzdCAgY2lzY28tbnNwQHB1Y2submV0aGVyLm5ldApodHRwczovL3B1Y2submV0 aGVyLm5ldC9tYWlsbWFuL2xpc3RpbmZvL2Npc2NvLW5zcAphcmNoaXZlIGF0IGh0dHA6Ly9wdWNr Lm5ldGhlci5uZXQvcGlwZXJtYWlsL2Npc2NvLW5zcC8K --===============0775384718846712582==--