<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL for  two interfaces on Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-for-two-interfaces-on-firewall/m-p/4033460#M1066832</link>
    <description>&lt;P&gt;I moved your post to&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-security/bd-p/discussions-network-security" target="_blank"&gt;Network Security&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;I would suggest you to follow the info at&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-documents/basic-troubleshooting-for-traffic-through-asa-firewall/ta-p/3162819" target="_blank"&gt;&lt;STRONG&gt;Basic Troubleshooting For traffic throu... - Cisco Community&lt;/STRONG&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 03:34:35 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2020-02-21T03:34:35Z</dc:date>
    <item>
      <title>ACL for  two interfaces on Firewall</title>
      <link>https://community.cisco.com/t5/network-security/acl-for-two-interfaces-on-firewall/m-p/4029422#M1066831</link>
      <description>&lt;P&gt;Hello guys,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am configuring&amp;nbsp; a Firewall (transparent mood) in between PLC and Field Bus Module ( Modbus to TCP, port 502 ).&amp;nbsp;&lt;/P&gt;&lt;P&gt;PLC and&amp;nbsp; Field Bus Module are in the same ip range and both are connected to firewall port 1 and 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall's port 1 and port 2 is part of same security level and traffic is permitted to travel within the same security level.&lt;/P&gt;&lt;P&gt;also&amp;nbsp; created BVI interface and added firewall's port 1 and 2 in to the same BVI group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what i would like to achieve:&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to block only port 1 can talk to&amp;nbsp; field bus module and port 2 can communicate via PLC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i wrote the bellow ACL.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;01. created an Object network and added the hosts :&lt;/P&gt;&lt;P&gt;object network PERMIT_PROD&lt;BR /&gt;host 192.168.1.100&lt;BR /&gt;object network PERMIT_PROD2&lt;BR /&gt;host 192.168.1.101&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;02. Access -List :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list&amp;nbsp;ACL_PERMIT_PROD extended permit ip object PERMIT_PROD host 192.168.1.1&lt;BR /&gt;access-list ACL_PERMIT_PROD2 extended permit ip object PERMIT_PROD2 host 192.168.1.1&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;access-group ACL_PERMIT_PROD in interface prod&lt;BR /&gt;access-group ACL_PERMIT_PROD2 in interface prod2&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;prod = nameif for&amp;nbsp; interface 1&amp;nbsp;&lt;/P&gt;&lt;P&gt;prod2 =nameif for interface 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Issues :&lt;/P&gt;&lt;P&gt;01. Firewall is not restricting the port 1 for&amp;nbsp; 192.168.1.100 and Port 2 192.168.1.101.&amp;nbsp; It can use vise versa.&lt;/P&gt;&lt;P&gt;question: Is that caused by&amp;nbsp; BVI interface ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any work around without removing it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;02. To make it communicate&amp;nbsp; only via modbus (port 502 )&amp;nbsp; do&amp;nbsp; i have to modify the ACL as bellow ? :&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list ACL_PERMIT_PROD2 extended permit ip object PERMIT_PROD2 host 192.168.1.1 &lt;EM&gt;&lt;STRONG&gt;eq 502&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your time.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:55:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-for-two-interfaces-on-firewall/m-p/4029422#M1066831</guid>
      <dc:creator>LANSK</dc:creator>
      <dc:date>2020-02-21T17:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: ACL for  two interfaces on Firewall</title>
      <link>https://community.cisco.com/t5/network-security/acl-for-two-interfaces-on-firewall/m-p/4033460#M1066832</link>
      <description>&lt;P&gt;I moved your post to&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-security/bd-p/discussions-network-security" target="_blank"&gt;Network Security&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;I would suggest you to follow the info at&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-documents/basic-troubleshooting-for-traffic-through-asa-firewall/ta-p/3162819" target="_blank"&gt;&lt;STRONG&gt;Basic Troubleshooting For traffic throu... - Cisco Community&lt;/STRONG&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 03:34:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-for-two-interfaces-on-firewall/m-p/4033460#M1066832</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-02-21T03:34:35Z</dc:date>
    </item>
  </channel>
</rss>

