ASA 5500: connection is still on after the ACL is modified

Sep 17, 2007 2 Replies

The answer may be simple but my searches could not show me any solution.



On my ASA 5510, I have an access-list that has an entry allowing the remote network to telnet to an internal host ( no NAT involved ) then I assign that list to the external interface . All work fine as expected.



Then I delete that access list entry. After that all *new* connections cannot get in but the connection already opened before I delete that entry is still there. I still be able to access the internal host thru that connection even the access list does not allow that operation any more.



How can I clear that alread-opened connection after I change the ACL ?



Thanks for your help,



DT



clear xlate....that will clear all the translations and they will rebuild themselves

Thanks, Brian, but I think xlate is for NAT translation table. I already tried that but the connection is still there. I still be able to access the server after the ACL has been droppped and clear xlate to be issued.

DT

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required