<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL logic, please confirm. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761081#M1097131</link>
    <description>&lt;P&gt;Yes, all traffic from inside would match the first rule and never match the more specific rules below.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 16:04:41 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2023-01-24T16:04:41Z</dc:date>
    <item>
      <title>ACL logic, please confirm.</title>
      <link>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4760968#M1097125</link>
      <description>&lt;P&gt;ACL logic, please confirm.&lt;/P&gt;&lt;P&gt;On an ASA 5525...&lt;/P&gt;&lt;P&gt;"access-list inside_in extended permit tcp host 172.16.0.2 host 1.1.1.1 eq 2222"&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is the following a true statement?&lt;/STRONG&gt;... "Host 172.16.0.2 &lt;STRONG&gt;using source port 5678 and destination port 2222&lt;/STRONG&gt; will be able to send, and during this same session receive, &lt;STRONG&gt;sftp traffic&lt;/STRONG&gt; to and from remote host 1.1.1.1 ."&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 13:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4760968#M1097125</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-01-24T13:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: ACL logic, please confirm.</title>
      <link>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761017#M1097126</link>
      <description>&lt;P&gt;This probably belongs here:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-security/bd-p/discussions-network-security" target="_blank"&gt;https://community.cisco.com/t5/network-security/bd-p/discussions-network-security&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;But yes; source = 172.16.0.2, destination = 1.1.1.1, destination port = TCP/2222, permit&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 14:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761017#M1097126</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-01-24T14:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACL logic, please confirm.</title>
      <link>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761043#M1097127</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1443661"&gt;@MicJameson1&lt;/a&gt; yes and assuming the correct direction and interface is configured - "access-group inside_in &lt;STRONG&gt;in&lt;/STRONG&gt; interface &lt;STRONG&gt;inside&lt;/STRONG&gt;"&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 15:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761043#M1097127</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-01-24T15:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: ACL logic, please confirm.</title>
      <link>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761070#M1097130</link>
      <description>&lt;P&gt;I only ask the basic below question because ASAs differ from other Cisco devices, and also the below config already exists in this active production ASA 5525...&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;access-list inside_in extended permit ip any any&lt;/STRONG&gt;&lt;BR /&gt;access-list inside_in extended permit tcp host 172.16.1.5 any eq 2222&lt;BR /&gt;access-list inside_in extended permit tcp host 172.16.1.5 any eq ssh&lt;BR /&gt;access-list inside_in extended permit tcp host 172.16.1.6 any eq ssh&lt;BR /&gt;access-list inside_in extended deny tcp any any eq ssh&lt;BR /&gt;access-list inside_in extended permit ip host 172.16.1.5 any"&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Doesn't the line "&lt;EM&gt;access-list inside_in extended permit ip any any&lt;/EM&gt;" make irrelevant the five lines below it?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 15:56:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761070#M1097130</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-01-24T15:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: ACL logic, please confirm.</title>
      <link>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761081#M1097131</link>
      <description>&lt;P&gt;Yes, all traffic from inside would match the first rule and never match the more specific rules below.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 16:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761081#M1097131</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-01-24T16:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACL logic, please confirm.</title>
      <link>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761104#M1097133</link>
      <description>&lt;P&gt;to check acl do&lt;BR /&gt;show access-list &amp;lt;&amp;lt;- then check the hitcnt,&amp;nbsp;&lt;BR /&gt;hitcnt will give fast review if the ACL permit/deny any traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 16:35:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761104#M1097133</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-24T16:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: ACL logic, please confirm.</title>
      <link>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761179#M1097144</link>
      <description>&lt;P&gt;Hi Rob.&lt;/P&gt;&lt;P&gt;May you also please answer these two questions?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt; "access-list inside_in extended deny tcp any any eq domain"-- &lt;STRONG&gt;Does this mean any elements that use tcp with a domain instead of an IP address will be blocked by the ACL?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt; "access-list inside_in extended deny tcp any any range 137 netbios-ssn"--&amp;nbsp;&lt;STRONG&gt;What does "range 137 netbios-ssn" mean?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thank you.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 18:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761179#M1097144</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-01-24T18:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACL logic, please confirm.</title>
      <link>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761193#M1097147</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1443661"&gt;@MicJameson1&lt;/a&gt; no, "domain" is the name for DNS over TCP on port 53. So that rule is denying an traffic on tcp/53.&lt;/P&gt;
&lt;P&gt;"netbios-ssn" is udp/139 - so essentially thats a range of 137-139&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 18:09:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-logic-please-confirm/m-p/4761193#M1097147</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-01-24T18:09:24Z</dc:date>
    </item>
  </channel>
</rss>

