ASA Order of Operation
This is the complete ASA Order of Operation in Routed Mode: - Virtual Firewall Classification
- IP packet security checks
- Fragmented IP traffic handling
- INPUT L2 ACL - Unlike L3/4 ACL, L2 ACL is per packet
- Flow look-up - If Fails, Continue; If Success, jump to Input QoS
- Additional packet security checks
- Addtional packet security checks (thru the box only)
- NP Inspect Engine Processing (ICMP/DNS/RTP/RTCP)
- CSC Module Processing (optional)
- Inspection Engine Processing/AAA punts/IPsec over TCP punts
- Address Update and Checksum Adjustments
- IPS - AIP Module processing (optional)
- Adjacency Look-up if necessary
- Queue processing and Transmit
No comments:
Post a Comment