<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: access-list on asa in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-list-on-asa/m-p/692492#M1036648</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assumed your ?group AC? has INSIDE_A &amp;amp; INSIDE_ C users, and access for this group from Inside to DMZ?s Lan_X is controlled by ?acl_inside?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, can user from INSIDE_C access Lan_X?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What?s the acl_inside entries and object-group for ?group AC? looks like?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Dec 2006 00:55:51 GMT</pubDate>
    <dc:creator>a.kiprawih</dc:creator>
    <dc:date>2006-12-13T00:55:51Z</dc:date>
    <item>
      <title>access-list on asa</title>
      <link>https://community.cisco.com/t5/network-security/access-list-on-asa/m-p/692491#M1036624</link>
      <description>&lt;P&gt;i have an asa 5510 which suppose to have the following rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. part of the inside users should be able to access the internet.&lt;/P&gt;&lt;P&gt;2. part of the inside users should be able to access a network on the DMZ&lt;/P&gt;&lt;P&gt;3. Part of the inside users should be able to access both the DMZ and the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;both http and https should be available on both outside and the dmz.&lt;/P&gt;&lt;P&gt;iam attaching a table which will explain my conventions used in my below config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_inside permit ip group AC any&lt;/P&gt;&lt;P&gt;access-list acl_lanX permit ip group BC lan_X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl_inside in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 3 access-list acl_lanX&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (outside) 1 192.168.1.1-192.168.1.250&lt;/P&gt;&lt;P&gt;global (dmz) 3 192.168.2.1-192.168.2.250&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with this config, users INSIDE_A cannot access lan_X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know why.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help and suugestions will be appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:08:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-on-asa/m-p/692491#M1036624</guid>
      <dc:creator>cfajardo1_2</dc:creator>
      <dc:date>2019-03-11T09:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: access-list on asa</title>
      <link>https://community.cisco.com/t5/network-security/access-list-on-asa/m-p/692492#M1036648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assumed your ?group AC? has INSIDE_A &amp;amp; INSIDE_ C users, and access for this group from Inside to DMZ?s Lan_X is controlled by ?acl_inside?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, can user from INSIDE_C access Lan_X?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What?s the acl_inside entries and object-group for ?group AC? looks like?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2006 00:55:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-on-asa/m-p/692492#M1036648</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-12-13T00:55:51Z</dc:date>
    </item>
  </channel>
</rss>

