36-15
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter36 Configuring a Service Policy
Managing the Order of Service Policy Rules
If the packet matches a subsequent rule for a different feature type, however, then the ASA also
applies the actions for the subsequent rule.
For example, if a packet matches a rule for connection limits, and also matches a rule for application
inspection, then both rule actions are applied.
If a packet matches a rule for application inspection, but also matches another rule that includes
application inspection, then the second rule actions are not applied.
If your rule includes an access list with multiple ACEs, then the order of ACEs also affects the packet
flow. The FWSM tests the packet against each ACE in the order in which the entries are listed. After a
match is found, no more ACEs are checked. For example, if you create an ACE at the beginning of an
access list that explicitly permits all traffic, no further statements are ever checked.
To change the order of rules or ACEs within a rule, perform the following steps:
Step1 From the Configuration > Firewall > Service Policy Rules pane, choose the rule or ACE that you want
to move up or down.
Step2 Click the Move Up or Move Down cursor (see Figure36-1).
Figure36-1 Moving an ACE
Note If you rearrange ACEs in an access list that is used in multiple service policies, then the change
is inherited in all service policies.
Step3 When you are done rearranging your rules or ACEs, click Apply.