<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA - Access List Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-access-list-configuration/m-p/2968590#M148692</link>
    <description>&lt;P&gt;Hi guys&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Wonder if someone can help. I'm trying to apply an access list on an ASA5505 (8.4) but having a slight problem. Overview is that I need a particular network to access some credit card machines. Below is the specific requirement followed by the related configuration on the firewall:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Request&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Additon of a firewall rule to allow traffic from the inside_Moomin&lt;/EM&gt; &lt;EM&gt;interface to&amp;nbsp;pixmark processing servers for&amp;nbsp;payment processing&amp;nbsp; &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Configuration&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;interface Vlan123&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;description MoominConnectivity&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;nameif InsideMoomin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;security-level 99&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;ip address 172.12.29.50 255.255.255.0&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object-group network&lt;BR /&gt;&amp;nbsp;network-object 172.12.29.0 255.255.255.0&lt;BR /&gt;object-group network NW_INLINE_NW_12&lt;BR /&gt;&amp;nbsp;network-object 172.12.29.0 255.255.255.0&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network PixmarkNetwork&lt;BR /&gt;&amp;nbsp;subnet 93.1.2.3 255.255.255.224&lt;BR /&gt;object network&amp;nbsp;PixmarkABC&lt;BR /&gt;&amp;nbsp;host 27.31.6.44&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network PixmarkServer&lt;BR /&gt;&amp;nbsp;host 93.4.5.6&lt;BR /&gt;object network&amp;nbsp;PixmarkAuth&lt;BR /&gt;&amp;nbsp;host 93.4.5.9&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object-group network NW_INLINE_NW_24&lt;BR /&gt;&amp;nbsp;network-object object PixmarkSM&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;EM&gt;object-group service PixmarkPorts&lt;BR /&gt;&amp;nbsp;description&amp;nbsp;Pixmark Payments System Ports&lt;BR /&gt;&amp;nbsp;service-object object 56275&lt;BR /&gt;&amp;nbsp;service-object object 32576&lt;BR /&gt;&amp;nbsp;service-object object 56630&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;I've tried adding the following but it doesn't accept the object-group for the ports&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;access-list InsideMoomin_access_in extended permit tcp object-group &lt;EM&gt;NW_INLINE_NW_12&lt;/EM&gt; object-group NW_INLINE_NW_24 object-group PixmarkPorts&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;I'd really appreciate any assistance. Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:30:36 GMT</pubDate>
    <dc:creator>BHconsultants88</dc:creator>
    <dc:date>2019-03-12T08:30:36Z</dc:date>
    <item>
      <title>ASA - Access List Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-list-configuration/m-p/2968590#M148692</link>
      <description>&lt;P&gt;Hi guys&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Wonder if someone can help. I'm trying to apply an access list on an ASA5505 (8.4) but having a slight problem. Overview is that I need a particular network to access some credit card machines. Below is the specific requirement followed by the related configuration on the firewall:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Request&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Additon of a firewall rule to allow traffic from the inside_Moomin&lt;/EM&gt; &lt;EM&gt;interface to&amp;nbsp;pixmark processing servers for&amp;nbsp;payment processing&amp;nbsp; &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Configuration&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;interface Vlan123&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;description MoominConnectivity&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;nameif InsideMoomin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;security-level 99&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;ip address 172.12.29.50 255.255.255.0&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object-group network&lt;BR /&gt;&amp;nbsp;network-object 172.12.29.0 255.255.255.0&lt;BR /&gt;object-group network NW_INLINE_NW_12&lt;BR /&gt;&amp;nbsp;network-object 172.12.29.0 255.255.255.0&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network PixmarkNetwork&lt;BR /&gt;&amp;nbsp;subnet 93.1.2.3 255.255.255.224&lt;BR /&gt;object network&amp;nbsp;PixmarkABC&lt;BR /&gt;&amp;nbsp;host 27.31.6.44&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network PixmarkServer&lt;BR /&gt;&amp;nbsp;host 93.4.5.6&lt;BR /&gt;object network&amp;nbsp;PixmarkAuth&lt;BR /&gt;&amp;nbsp;host 93.4.5.9&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object-group network NW_INLINE_NW_24&lt;BR /&gt;&amp;nbsp;network-object object PixmarkSM&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;EM&gt;object-group service PixmarkPorts&lt;BR /&gt;&amp;nbsp;description&amp;nbsp;Pixmark Payments System Ports&lt;BR /&gt;&amp;nbsp;service-object object 56275&lt;BR /&gt;&amp;nbsp;service-object object 32576&lt;BR /&gt;&amp;nbsp;service-object object 56630&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;I've tried adding the following but it doesn't accept the object-group for the ports&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;access-list InsideMoomin_access_in extended permit tcp object-group &lt;EM&gt;NW_INLINE_NW_12&lt;/EM&gt; object-group NW_INLINE_NW_24 object-group PixmarkPorts&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;I'd really appreciate any assistance. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:30:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-list-configuration/m-p/2968590#M148692</guid>
      <dc:creator>BHconsultants88</dc:creator>
      <dc:date>2019-03-12T08:30:36Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-list-configuration/m-p/2968591#M148693</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Once you have defined the protocol-type in the object, you do not need to define it again.&lt;/P&gt;
&lt;P&gt;Try this please:&lt;/P&gt;
&lt;P&gt;access-list test-access extended permit object-group &lt;STRONG&gt;PixmarkPorts&lt;/STRONG&gt; object-group NW_INLINE_NW_12 object-group NW_INLINE_NW_24&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Should look like this, this is from my lab device:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;access-list test-access line 1 extended permit object-group PixmarkPorts object-group NW_INLINE_NW_12 object-group NW_INLINE_NW_24 (hitcnt=0) 0x1157a579 &lt;BR /&gt;&amp;nbsp;&lt;STRONG&gt; access-list test-access line 1 extended permit tcp 172.12.29.0 255.255.255.0 93.1.1.0 255.255.255.0 eq 32576 (hitcnt=0) 0xde550957&lt;/STRONG&gt; &lt;BR /&gt;&amp;nbsp; &lt;STRONG&gt;access-list test-access line 1 extended permit tcp 172.12.29.0 255.255.255.0 93.1.1.0 255.255.255.0 eq 56275 (hitcnt=0) 0xe&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;object network test&lt;BR /&gt;&amp;nbsp;subnet 172.12.29.0 255.255.255.0&lt;BR /&gt;object network test1&lt;BR /&gt;&amp;nbsp;subnet 93.1.1.0 255.255.255.0&lt;BR /&gt;object service test-port&lt;BR /&gt;&amp;nbsp;service tcp destination eq 32576 &lt;BR /&gt;object service test-port1&lt;BR /&gt;&amp;nbsp;service tcp destination eq 56275&lt;/P&gt;
&lt;P&gt;ciscoasa(config)# &lt;STRONG&gt;sh run object-group id PixmarkPorts&lt;/STRONG&gt;&lt;BR /&gt;object-group service PixmarkPorts&lt;BR /&gt;&amp;nbsp;service-object object test-port &lt;BR /&gt;&amp;nbsp;service-object object test-port1 &lt;BR /&gt;ciscoasa(config)# &lt;STRONG&gt;sh run object-group id NW_INLINE_NW_12&lt;/STRONG&gt;&lt;BR /&gt;object-group network NW_INLINE_NW_12&lt;BR /&gt;&amp;nbsp;network-object object test&lt;BR /&gt;ciscoasa(config)# &lt;STRONG&gt;sh run object-group id NW_INLINE_NW_24&lt;/STRONG&gt;&lt;BR /&gt;object-group network NW_INLINE_NW_24&lt;BR /&gt;&amp;nbsp;network-object object test1&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Kanwal&lt;/P&gt;
&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2016 20:09:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-list-configuration/m-p/2968591#M148693</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2016-11-09T20:09:26Z</dc:date>
    </item>
  </channel>
</rss>

