<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic access-group every access-list? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719802#M1009367</link>
    <description>&lt;P&gt;Basic config question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I have add an initial access-list rule (no others are defined yet):&lt;/P&gt;&lt;P&gt;access-list outbound permit icmp any any&lt;/P&gt;&lt;P&gt;access-group outbound in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AND then I want to add another access-list rule:&lt;/P&gt;&lt;P&gt;access-list outbound permit tcp 192.168.0.0 255.255.255.0 any eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to specicy the access-group command with each subsequent access-list rule I add to the same ID?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:51:22 GMT</pubDate>
    <dc:creator>srberg5219</dc:creator>
    <dc:date>2019-03-11T09:51:22Z</dc:date>
    <item>
      <title>access-group every access-list?</title>
      <link>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719802#M1009367</link>
      <description>&lt;P&gt;Basic config question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I have add an initial access-list rule (no others are defined yet):&lt;/P&gt;&lt;P&gt;access-list outbound permit icmp any any&lt;/P&gt;&lt;P&gt;access-group outbound in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AND then I want to add another access-list rule:&lt;/P&gt;&lt;P&gt;access-list outbound permit tcp 192.168.0.0 255.255.255.0 any eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to specicy the access-group command with each subsequent access-list rule I add to the same ID?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719802#M1009367</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2019-03-11T09:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: access-group every access-list?</title>
      <link>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719803#M1009368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no.you do not need to add access-g command for each access-list statement with the same id.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-g applies the access-list on an interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create n number of access-lists with the name of outbound.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create one access-g command with the same id and apply that on any of the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remember,you can apply an access-list " let's say " outbound " on only one interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;sushil&lt;/P&gt;&lt;P&gt;cisco tac&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2007 16:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719803#M1009368</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2007-03-23T16:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: access-group every access-list?</title>
      <link>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719804#M1009369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One last question. This is running on a PIX 506 with software version 5.1(2). I am stuck with this version as I do not have the appropriate clearances to download the most recent software as this was purchased pre-owned from a company...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;When I add static commands (to allow access from the outside into a server on my network) do I need to use the correct network netmask or a generic 255.255.255.255 netmask?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;Is this correct:&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.254.50 192.168.0.10 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR IS THIS CORRECT:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.254.50 192.168.0.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2007 17:47:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719804#M1009369</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2007-03-23T17:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: access-group every access-list?</title>
      <link>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719805#M1009370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the second one is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2007 17:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719805#M1009370</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2007-03-23T17:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: access-group every access-list?</title>
      <link>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719806#M1009371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe just one more config question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server A (IP 192.168.0.50): Front-end MS Exchange Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can add a static command (and appropriate ACLs) as follows to allow access on port 25:&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.254.25 192.168.0.50 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then when I go to add another static command to allow POP3 access on the same server as follows:&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.254.110 192.168.0.50 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I receive the following message:&lt;/P&gt;&lt;P&gt;192.168.0.50: That address already statically translated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(This server will actually need to be accessible for 3 protocols: SMTP, POP3 and HTTPS-for OWA)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparently I am missing something and have searched all my manuals and Google to no avail...Do I combine all 3 protocols into one static command? If so, how do I format the 'eq' portion? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2007 19:46:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719806#M1009371</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2007-03-23T19:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: access-group every access-list?</title>
      <link>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719807#M1009372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;lets say,the public ip address of this mail server is : 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then you need to map 1.1.1.1 to internal private ip address of mail server 192.168.0.50.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.1.1 192.168.0.50 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as far as ports are concerned,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here's the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list out_in permit tcp any host 1.1.1.1 eq 110&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list out_in permit tcp any host 1.1.1.1 eq 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list out_in permit tcp any host 1.1.1.1 eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-g out_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so,we created a static mapping public ip of mail to its private ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we created access-lists on outside interface to permit the ports we need to open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sushil&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2007 19:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719807#M1009372</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2007-03-23T19:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: access-group every access-list?</title>
      <link>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719808#M1009373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DOH! I was thinking in the wrong direction!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My deepest gartitude for helping me learn!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2007 19:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-group-every-access-list/m-p/719808#M1009373</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2007-03-23T19:52:43Z</dc:date>
    </item>
  </channel>
</rss>

