<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA ACL Help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-acl-help/m-p/4508471#M1085378</link>
    <description>&lt;P class=""&gt;Those ACLs are permitting and denying IPs, protocols, etc…, for example:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;access-list outside-acl line 1 extended permit tcp any interface outside eq 3389:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Permits tcp from any interface to outside. That applies when equals to port 3389 &amp;nbsp;which used for&amp;nbsp;&lt;STRONG&gt;Microsoft WBT Server&lt;/STRONG&gt;, used for Windows Remote Desktop and Remote Assistance connections (RDP - Remote Desktop Protocol).&lt;/P&gt;&lt;P class=""&gt;ASA has an implicit deny.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;I would read the following documentation for better understanding:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html#ID-2069-0000011a" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html#ID-2069-0000011a&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/ios-firewall/23602-confaccesslists.html?referring_site=RE&amp;amp;pos=3&amp;amp;page=https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/ios-firewall/23602-confaccesslists.html?referring_site=RE&amp;amp;pos=3&amp;amp;page=https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;In addition, if you have some spare time you can read this book which not only will teach about ACLs but ASA overall:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://www.amazon.com/dp/1587143070?tag=uuid10-20" target="_blank" rel="noopener"&gt;https://www.ciscopress.com/store/cisco-asa-all-in-one-next-generation-firewall-ips-and-9781587143076&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Nov 2021 18:58:16 GMT</pubDate>
    <dc:creator>BmfL</dc:creator>
    <dc:date>2021-11-25T18:58:16Z</dc:date>
    <item>
      <title>ASA ACL Help</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-help/m-p/4508462#M1085376</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fairly new to ASA, have done some limited work in the past.&amp;nbsp; Wondering if someone could give me a quick run down on what the following ACL statements do and, following the last statement, is it implicit "deny"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list outside-acl; 4 elements; name hash: 0x9bea1c52&lt;/P&gt;&lt;P&gt;access-list outside-acl line 1 extended permit tcp any interface outside eq 3389&lt;/P&gt;&lt;P&gt;access-list outside-acl line 2 remark Allow pinging of firewall&lt;/P&gt;&lt;P&gt;access-list outside-acl line 3 extended permit icmp any interface outside echo&lt;/P&gt;&lt;P&gt;access-list outside-acl line 4 extended permit icmp any interface outside echo-reply&lt;/P&gt;&lt;P&gt;access-list outside-acl line 5 extended deny ip any any log informational interval 300&lt;/P&gt;&lt;P&gt;access-list dmz-acl; 4 elements; name hash: 0x282e44f8&lt;/P&gt;&lt;P&gt;access-list dmz-acl line 1 extended permit udp any any eq ntp&lt;/P&gt;&lt;P&gt;access-list dmz-acl line 2 extended permit ip any host 10.74.0.27&lt;/P&gt;&lt;P&gt;access-list dmz-acl line 3 extended permit ip host 172.22.12.16 any log informational interval 300&lt;/P&gt;&lt;P&gt;access-list dmz-acl line 4 remark 'allow backup'&lt;/P&gt;&lt;P&gt;access-list dmz-acl line 5 extended permit ip any host 10.101.0.160&lt;/P&gt;&lt;P&gt;access-list nat-acl; 1 elements; name hash: 0xf4b526c2&lt;/P&gt;&lt;P&gt;access-list nat-acl line 1 extended permit ip 172.22.0.0 255.255.0.0 any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 18:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-help/m-p/4508462#M1085376</guid>
      <dc:creator>newbiefromfortinet</dc:creator>
      <dc:date>2021-11-25T18:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ACL Help</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-help/m-p/4508471#M1085378</link>
      <description>&lt;P class=""&gt;Those ACLs are permitting and denying IPs, protocols, etc…, for example:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;access-list outside-acl line 1 extended permit tcp any interface outside eq 3389:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Permits tcp from any interface to outside. That applies when equals to port 3389 &amp;nbsp;which used for&amp;nbsp;&lt;STRONG&gt;Microsoft WBT Server&lt;/STRONG&gt;, used for Windows Remote Desktop and Remote Assistance connections (RDP - Remote Desktop Protocol).&lt;/P&gt;&lt;P class=""&gt;ASA has an implicit deny.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;I would read the following documentation for better understanding:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html#ID-2069-0000011a" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html#ID-2069-0000011a&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/ios-firewall/23602-confaccesslists.html?referring_site=RE&amp;amp;pos=3&amp;amp;page=https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/ios-firewall/23602-confaccesslists.html?referring_site=RE&amp;amp;pos=3&amp;amp;page=https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;In addition, if you have some spare time you can read this book which not only will teach about ACLs but ASA overall:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://www.amazon.com/dp/1587143070?tag=uuid10-20" target="_blank" rel="noopener"&gt;https://www.ciscopress.com/store/cisco-asa-all-in-one-next-generation-firewall-ips-and-9781587143076&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 18:58:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-help/m-p/4508471#M1085378</guid>
      <dc:creator>BmfL</dc:creator>
      <dc:date>2021-11-25T18:58:16Z</dc:date>
    </item>
  </channel>
</rss>

