<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA VTI interfaces and access rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3296797#M1010348</link>
    <description>MArc, you can use the ACL manager to add rules to the Accees list once it is applied to the interface. rather than use the CLI</description>
    <pubDate>Fri, 15 Dec 2017 12:01:03 GMT</pubDate>
    <dc:creator>Aaron Street</dc:creator>
    <dc:date>2017-12-15T12:01:03Z</dc:date>
    <item>
      <title>ASA VTI interfaces and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3230746#M1010341</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you add Access Rules to A VTI interface in ASA 9.8?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see the tunnel interface showing as up in the ASDM, and I can ping the end points from the CLI, but when I chose "Add access rule" in the ASDM&amp;nbsp; the list of interfaces does not include my tunnel?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aaron&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3230746#M1010341</guid>
      <dc:creator>Aaron Street</dc:creator>
      <dc:date>2020-02-21T14:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VTI interfaces and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3230887#M1010344</link>
      <description>&lt;P&gt;You should be able to add an ACL to the VTI interface.&lt;/P&gt;
&lt;P&gt;You could try applying the&amp;nbsp;ACL via CLI:&lt;/P&gt;
&lt;P&gt;access-group ACL-VTI-IN in interface VTI&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"• Access list can be applied on a VTI interface to control traffic through VTI."&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/vpn/asa-97-vpn-config/vpn-vti.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/vpn/asa-97-vpn-config/vpn-vti.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3230887#M1010344</guid>
      <dc:creator>Bogdan Nita</dc:creator>
      <dc:date>2017-12-12T15:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VTI interfaces and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3296726#M1010346</link>
      <description>&lt;P&gt;Great hint, much appreciated! This works for me. After aplying&amp;nbsp;access-group to&amp;nbsp;VTI Interface&amp;nbsp;via CLI and refreshing the ASDM the access-list is also displayed in the GUI and can be modified as usual. But the Interface is still not available if you want to add an new entry - you still need the CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Katrin&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 10:21:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3296726#M1010346</guid>
      <dc:creator>MarcBrechbuehl</dc:creator>
      <dc:date>2017-12-15T10:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VTI interfaces and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3296795#M1010347</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did add an ACL to the interface via the CLI, but I still can't add rules to the ACL via the access rule GUI interface? I assume this is a limitation of VTI interfaces.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems the ASDM does not recognize VTI interfaces in this way&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 11:59:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3296795#M1010347</guid>
      <dc:creator>Aaron Street</dc:creator>
      <dc:date>2017-12-15T11:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VTI interfaces and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3296797#M1010348</link>
      <description>MArc, you can use the ACL manager to add rules to the Accees list once it is applied to the interface. rather than use the CLI</description>
      <pubDate>Fri, 15 Dec 2017 12:01:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3296797#M1010348</guid>
      <dc:creator>Aaron Street</dc:creator>
      <dc:date>2017-12-15T12:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VTI interfaces and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3999045#M1010349</link>
      <description>&lt;P&gt;did you create your access-group?&lt;/P&gt;&lt;P&gt;first you want to make sure to create your ACL first, then create the access-group&lt;/P&gt;&lt;P&gt;creating access-group before the ACL will not work. it is part of the cisco mechanics.&lt;/P&gt;&lt;P&gt;there is no limitations for the VTI in terms of ACL,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try this: &amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list &lt;STRONG&gt;nameif-VTI_in&lt;/STRONG&gt; deny ip any any&lt;/P&gt;&lt;P&gt;access-group &lt;STRONG&gt;nameif-VTI_in&lt;/STRONG&gt; in interface &lt;STRONG&gt;VTI-Interface&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Dec 2019 08:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vti-interfaces-and-access-rules/m-p/3999045#M1010349</guid>
      <dc:creator>john.colet@intact.net</dc:creator>
      <dc:date>2019-12-15T08:57:50Z</dc:date>
    </item>
  </channel>
</rss>

