1-7
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Access Rules
Guidelines and Limitations
Guidelines and Limitations
This section includes the guidelines and limitations for this feature.
Context Mode Guidelines
Supported in single and multiple context mode.
Firewall Mode Guidelines
Supported in routed and transparent firewall modes.
IPv6 Guidelines
Supports IPv6. The source and destination addresses can include any mix of IPv4 and IPv6 addresses.
Per-User Access List Guidelines
• If there is no per-user access list associated with a packet, the interface access rule is applied.
• The per-user access list uses the value in the timeout uauth command, but it can be overridden by
the AAA per-user session timeout value.
• If traffic is denied because of a per-user access list, syslog message 109025 is logged. If traffic is
permitted, no syslog message is generated. The log option in the per-user access list has no effect.
Default Settings
See the “Implicit Permits” section on page 1-2.
Configuring Access Rules
To apply an access rule, perform the following steps.