<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block internet on one device in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290784#M1078428</link>
    <description>&lt;P&gt;Not sure how your ASA configuration to suggest - based on the exiting config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so please look below document using ASDM add ACL and test &amp;amp; advise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0000743" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0000743&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Feb 2021 14:11:37 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-02-12T14:11:37Z</dc:date>
    <item>
      <title>Block internet on one device</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290779#M1078427</link>
      <description>&lt;P&gt;What is the proper ACL to block internet on one server using an ASA 5545 version 9.6(4) 20?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 13:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290779#M1078427</guid>
      <dc:creator>Eddie Sardinha</dc:creator>
      <dc:date>2021-02-12T13:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet on one device</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290784#M1078428</link>
      <description>&lt;P&gt;Not sure how your ASA configuration to suggest - based on the exiting config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so please look below document using ASDM add ACL and test &amp;amp; advise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0000743" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0000743&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 14:11:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290784#M1078428</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-02-12T14:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet on one device</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290788#M1078429</link>
      <description>&lt;P&gt;Alternately, you could delete a default route on the server itself and only use specific routes.&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 14:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290788#M1078429</guid>
      <dc:creator>rais</dc:creator>
      <dc:date>2021-02-12T14:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet on one device</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290799#M1078430</link>
      <description>&lt;P&gt;What is the proper ACL to block internet on one server using an ASA 5545 version 9.6(4) 20?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EXAMPLE&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;PRE&gt;interface gig1/5&lt;BR /&gt; nameif DMZ&lt;BR /&gt; sec 50&lt;BR /&gt; ip address 192.168.x.x 255.255.x.x&lt;BR /&gt;!&lt;BR /&gt;object-group network RFC1918
 10.0.0.0 255.0.0.0
 172.16.0.0 255.240.0.0
 192.168.0.0 255.255.0.0&lt;BR /&gt;!&lt;BR /&gt;object network SERVER-DMZ&lt;BR /&gt; host 192.168.x.x   ---THIS IS YOUR SERVER NEED STOP ACCESS TO INTERNET----&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;PRE&gt;access-list DMZ_IN extended permit ip SERVER-DMZ object-group RFC1918&lt;BR /&gt;access-list DMZ_IN extended deny ip SERVER-DMZ any&lt;BR /&gt;!&lt;BR /&gt;access-group DMZ_IN in interface DMZ&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 17:37:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290799#M1078430</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2021-02-12T17:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet on one device</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290877#M1078439</link>
      <description>&lt;P&gt;I have a lot of other ACL's part of different interfaces, inside, outside, dmz and transit interfaces.&amp;nbsp; &amp;nbsp;I want to be sure this doesnt block anything from other devices in my network.&amp;nbsp; Do I need to do anything so nothing else gets blocked ?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 16:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290877#M1078439</guid>
      <dc:creator>Eddie Sardinha</dc:creator>
      <dc:date>2021-02-12T16:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet on one device</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290885#M1078440</link>
      <description>&lt;P&gt;Which interfere on this ASA this server belong to?&amp;nbsp;&lt;BR /&gt;and what access list you have configured on this interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you share the internet name of this sever and the first line of access list I can write the ACL for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;example&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;access-list DMZ_IN inline 1 extended  permit ip SERVER-DMZ object-group RFC1918
access-list DMZ_IN inline 2 extended deny ip SERVER-DMZ any
access-list DMZ_IN inline 3 extended permit ip xxx.xxx. xxx.xxxx
....................................................
.....................................................
!
access-group DMZ_IN in interface DMZ&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 17:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290885#M1078440</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2021-02-12T17:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet on one device</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290888#M1078441</link>
      <description>&lt;P&gt;If you have too many ACL not able to post complete config, not confident enough where to add, best is use ASDM&amp;nbsp; add Line below or above where required - test if not working easy from GUI to disable or ammend.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since ASA generate lot of ACL command level, some time it hard to figure out where to insert this lines and as you mentioned this may cause other issue, so please use GUI is easy for simplicity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 16:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290888#M1078441</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-02-12T16:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet on one device</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290941#M1078445</link>
      <description>&lt;P&gt;The server should be behind the inside interface but i can't share the names of the servers&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 18:33:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-on-one-device/m-p/4290941#M1078445</guid>
      <dc:creator>Eddie Sardinha</dc:creator>
      <dc:date>2021-02-12T18:33:10Z</dc:date>
    </item>
  </channel>
</rss>

