<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hi Jon, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/4105691#M1071195</link>
    <description>&lt;P&gt;I have tried this command on my ASA 5540, with 9.x IOS, and the following occurred:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ciscoasa5540(config)# shun 65.197.196.0 netmask 255.255.255.0&lt;BR /&gt;^&lt;BR /&gt;ERROR: % Invalid Hostname&lt;BR /&gt;ciscoasa5540(config)# shun 65.197.196.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please let me know how this is done correctly?&amp;nbsp; Thank you very much!&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jun 2020 15:16:10 GMT</pubDate>
    <dc:creator>beatinger</dc:creator>
    <dc:date>2020-06-18T15:16:10Z</dc:date>
    <item>
      <title>Block external subnet with asa</title>
      <link>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924159#M166980</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a cisco asa 5510 and would like to block a public subnet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could some tell me how i can block a whole subnet with an access list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924159#M166980</guid>
      <dc:creator>mspdog22</dc:creator>
      <dc:date>2019-03-12T07:53:08Z</dc:date>
    </item>
    <item>
      <title>Hi Jon,</title>
      <link>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924160#M166982</link>
      <description>&lt;P&gt;Hi Jon,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can use the deny statement on the outside access-list applied in the out direction on the interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can also use the shun command to deny the public IP subnet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;shun x.x.x.x netmask x.x.x.x&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 16:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924160#M166982</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-06-14T16:03:39Z</dc:date>
    </item>
    <item>
      <title>Not sure i understand. </title>
      <link>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924161#M166983</link>
      <description>&lt;P&gt;Not sure i understand.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you post a sample config of the access list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 16:20:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924161#M166983</guid>
      <dc:creator>mspdog22</dc:creator>
      <dc:date>2016-06-14T16:20:24Z</dc:date>
    </item>
    <item>
      <title>I am trying to block our</title>
      <link>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924162#M166986</link>
      <description>&lt;P&gt;I am trying to block our inside users from being able to access Netflix.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have all the subnet that Netflix owns and there ip space.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I plan to build and access list that will block all traffic from inside to outside interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 16:28:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924162#M166986</guid>
      <dc:creator>mspdog22</dc:creator>
      <dc:date>2016-06-14T16:28:48Z</dc:date>
    </item>
    <item>
      <title>create object group and</title>
      <link>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924163#M166988</link>
      <description>&lt;P&gt;create object group and include all netflix ip,=&amp;gt;deny (source any destination netflix-subnet service IP ) &amp;nbsp;apply in your internal or DMZ interface depend on your traffic route&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 16:47:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924163#M166988</guid>
      <dc:creator>OPRoger</dc:creator>
      <dc:date>2016-06-14T16:47:13Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924164#M166991</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You need to apply the access-list on the inside interface as shown in this example:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Block the HTTP port traffic:&lt;/P&gt;
&lt;P&gt;In order to block the inside network 10.1.1.0 from access to the &lt;G class="gr_ gr_105 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="105" data-gr-id="105"&gt;http&lt;/G&gt; (web server) with IP 1.1.1.1 placed &lt;G class="gr_ gr_103 gr-alert gr_gramm gr_run_anim Grammar multiReplace" id="103" data-gr-id="103"&gt;in&lt;/G&gt; the outside network, create an ACL as shown:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;G class="gr_ gr_107 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="107" data-gr-id="107"&gt;ciscoasa&lt;/G&gt;(config)#access-list 100 extended deny &lt;G class="gr_ gr_108 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="108" data-gr-id="108"&gt;tcp&lt;/G&gt; 10.1.1.0 255.255.255.0 &lt;BR /&gt;host 172.16.1.1 eq 80&lt;BR /&gt;&lt;G class="gr_ gr_109 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="109" data-gr-id="109"&gt;ciscoasa&lt;/G&gt;(config)#access-list 100 extended permit &lt;G class="gr_ gr_110 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="110" data-gr-id="110"&gt;ip&lt;/G&gt; any any&lt;BR /&gt;&lt;G class="gr_ gr_106 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="106" data-gr-id="106"&gt;ciscoasa&lt;/G&gt;(config)#access-group 100 in interface inside&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 00:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/2924164#M166991</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-06-15T00:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Jon,</title>
      <link>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/4105691#M1071195</link>
      <description>&lt;P&gt;I have tried this command on my ASA 5540, with 9.x IOS, and the following occurred:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ciscoasa5540(config)# shun 65.197.196.0 netmask 255.255.255.0&lt;BR /&gt;^&lt;BR /&gt;ERROR: % Invalid Hostname&lt;BR /&gt;ciscoasa5540(config)# shun 65.197.196.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please let me know how this is done correctly?&amp;nbsp; Thank you very much!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 15:16:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-external-subnet-with-asa/m-p/4105691#M1071195</guid>
      <dc:creator>beatinger</dc:creator>
      <dc:date>2020-06-18T15:16:10Z</dc:date>
    </item>
  </channel>
</rss>

