<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi , in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932635#M1029442</link>
    <description>Hi ,

Rule 2  has URL's in it you should add only the name as in google.com instead of http and https in there .

Regards,
Aastha Bhardwaj
Rate if that helps!!!</description>
    <pubDate>Fri, 09 Sep 2016 12:39:30 GMT</pubDate>
    <dc:creator>Aastha Bhardwaj</dc:creator>
    <dc:date>2016-09-09T12:39:30Z</dc:date>
    <item>
      <title>Best Practice to create Access Control Policy</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932632#M1029439</link>
      <description>&lt;P&gt;Hello Friends! I need an advice.How better to create rules for access control policy? I had not practice.&lt;BR /&gt;How I do that.&lt;BR /&gt;1.Policies -&amp;gt; access control -&amp;gt; Here create My Policy&lt;BR /&gt;2.In my new policy I can create different rules, which can either block or allow.&lt;BR /&gt;For example I have rule 1 (it inspect my network use intrusion policy and inspect files).&lt;BR /&gt;rule2 - I want to deny access one of my computer to sait.I use BLOCK action and it works!&lt;/P&gt;
&lt;P&gt;Is it right to use rules or maybe i do it wrong?&lt;/P&gt;
&lt;P&gt;P.S. I used the follow structure of the network: &lt;BR /&gt;WAN - ASA - FIREPOWER - LAN (asa and firepower work separately, i do not use modules for asa, i have firepower and fire sight)&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:07:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932632#M1029439</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2019-03-12T13:07:47Z</dc:date>
    </item>
    <item>
      <title>Hello!Trying to understand.I</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932633#M1029440</link>
      <description>&lt;P&gt;Hello!Trying to understand.&lt;BR /&gt;I have problems with 2 rules (rule 2 and rule 4). Rule 2 must block sites for one computer.And rule 4 must block utorrent.&lt;BR /&gt;Rule 4 is working. But rule 2 is not working (it working only if rule 4 disabled). What I do not right? Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 12:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932633#M1029440</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-09-09T12:28:08Z</dc:date>
    </item>
    <item>
      <title>Hi ,</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932634#M1029441</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I would suggest you to create Block statement on top because it is specific to 1 PC , the rules are matched from top to bottom , so if the rule matches first it wont even look for other rules . So more specific rules should be places on top and then followed by generic rules.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 12:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932634#M1029441</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2016-09-09T12:36:15Z</dc:date>
    </item>
    <item>
      <title>Hi ,</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932635#M1029442</link>
      <description>Hi ,

Rule 2  has URL's in it you should add only the name as in google.com instead of http and https in there .

Regards,
Aastha Bhardwaj
Rate if that helps!!!</description>
      <pubDate>Fri, 09 Sep 2016 12:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932635#M1029442</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2016-09-09T12:39:30Z</dc:date>
    </item>
    <item>
      <title>Thank you for your time! I</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932636#M1029443</link>
      <description>&lt;P&gt;Thank you for your time! I try to change names of sites, but it is not working.&lt;/P&gt;
&lt;P&gt;But if I disabled rule&amp;nbsp;4 (must block utorrent) - rule 2 start to work. And computers do not have an access to this sites. Thank you!!!&lt;/P&gt;
&lt;P&gt;I add my policy.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 13:41:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932636#M1029443</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-09-09T13:41:13Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932637#M1029444</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Are there any errors beside your rules when you have them in the order that they are in? (Yellow Triangle with explanation point)?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, have you tried switching those two rules spots, to see if that would affect the top - down matching criteria.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 13:50:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932637#M1029444</guid>
      <dc:creator>sebrjohnson</dc:creator>
      <dc:date>2016-09-09T13:50:31Z</dc:date>
    </item>
    <item>
      <title>O! I have not errors. And  i</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932638#M1029445</link>
      <description>&lt;P&gt;O! I have not errors. And &amp;nbsp;i tryed to&amp;nbsp;interchange the position of rules. And no effect.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 14:09:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932638#M1029445</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-09-09T14:09:01Z</dc:date>
    </item>
    <item>
      <title>Since Rule 4 works and rule</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932639#M1029447</link>
      <description>&lt;P&gt;Since Rule 4 works and rule two doesn't;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Try removing the all the filters on rule two except the URLs that you don't want to access. Do you want them to be an "interactive block"?&lt;/P&gt;
&lt;P&gt;=Rule2= "any""any", then URLs, and Block&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 14:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932639#M1029447</guid>
      <dc:creator>sebrjohnson</dc:creator>
      <dc:date>2016-09-09T14:24:12Z</dc:date>
    </item>
    <item>
      <title>Thank you! Now it is ok! But</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932640#M1029449</link>
      <description>&lt;P&gt;Hello! I need an advice.&lt;/P&gt;
&lt;P&gt;I have access policy and I do not know use it right or not?&lt;/P&gt;
&lt;P&gt;Is it need to add rule with INTRUSION POLICY or it will be used as default (default action)?&lt;/P&gt;
&lt;P&gt;And I want to detect files. Do I need to use it as a individual rule. Or I need to use it with intrusion policy? (7)&lt;/P&gt;
&lt;P&gt;Thank you!!!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2016 08:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-to-create-access-control-policy/m-p/2932640#M1029449</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-09-23T08:48:48Z</dc:date>
    </item>
  </channel>
</rss>

