<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prioritising local firewall rules with global rules also on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/prioritising-local-firewall-rules-with-global-rules-also-on-asa/m-p/5075254#M1111520</link>
    <description>&lt;P&gt;can you more elaborate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 22 Apr 2024 13:48:20 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-04-22T13:48:20Z</dc:date>
    <item>
      <title>Prioritising local firewall rules with global rules also on ASA</title>
      <link>https://community.cisco.com/t5/network-security/prioritising-local-firewall-rules-with-global-rules-also-on-asa/m-p/5075187#M1111513</link>
      <description>&lt;P&gt;&lt;SPAN&gt;How to prioritise local firewall rules when global rules are also configured in Cisco ASA firewalls managed in CSM&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;A way for local rules to get checked first when global rules are also configured in Cisco ASA firewalls managed in CSM&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;With rule inheritance, we can have a local device contain the rules defined in a shared "global" policy in addition to local rules.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;CSM can enforce a hierarchy where policies at a lower level (called child policies) inherit the rules of policies defined above them in the hierarchy (called parent policies).&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt; &lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Unfortunately, I ran into this issue that a local subnet would still get access to whatever the first half of the "global" policy allows (above the local rules).&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;In other words, securing a local subnet with local rules can be tricky when global policies are associated with ASA firewalls in CSM because one half of the "global" policies precedes the local rules and so an isolated subnet will still get access to whatever the preceding global rules allow.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;A solution is to create a “DENY-GLOBAL” policy which has only those deny rules that we want to apply on a particular ASA firewall.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Then, we subordinate the actual “GLOBAL POLICY” - as a child policy – to the “DENY-GLOBAL” policy (which will be the parent policy).&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Then we associate this bespoke policy with the firewalls.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;This way, any changes to the global policy are still automatically updated in the global policy.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;To make this more scalable, we could use the override function in the objects used in the “DENY-GLOBAL” parent policy so that one policy can be used on different firewalls.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 12:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/prioritising-local-firewall-rules-with-global-rules-also-on-asa/m-p/5075187#M1111513</guid>
      <dc:creator>ArpadPapp</dc:creator>
      <dc:date>2024-04-22T12:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Prioritising local firewall rules with global rules also on ASA</title>
      <link>https://community.cisco.com/t5/network-security/prioritising-local-firewall-rules-with-global-rules-also-on-asa/m-p/5075254#M1111520</link>
      <description>&lt;P&gt;can you more elaborate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 13:48:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/prioritising-local-firewall-rules-with-global-rules-also-on-asa/m-p/5075254#M1111520</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-22T13:48:20Z</dc:date>
    </item>
  </channel>
</rss>

