access-control to block core traffic
Hello,
I was trying a scenario to generate SA down by blocking the OPTION messages from SBC (core interface) to SA. Question is, can we apply access-control list on core (inside) realm. I tried this acl but didn't work. Any idea how can I do this ?
access-control
realm-id IPV4Core
description
source-address 10.20.224.211
destination-address 172.16.24.10:5060
application-protocol SIP
transport-protocol ALL
access deny
average-rate-limit 0
trust-level high
minimum-reserved-bandwidth 0
invalid-signal-threshold 1
maximum-signal-threshold 30000
untrusted-signal-threshold 0
deny-period 30
nat-trust-threshold 0
max-endpoints-per-nat 0
nat-invalid-message-threshold 0
cac-failure-threshold 0
untrust-cac-failure-threshold 0
last-modified-by admin@10.71.37.90
last-modified-date 2014-04-14 17:54:51