<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic acl on asa in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-on-asa/m-p/2860072#M171779</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help me to understand how the acl works on asa code 9.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i want to block a host (&lt;SPAN&gt;172.16.10.250) &lt;/SPAN&gt;from dmz&amp;nbsp; zone to outside (internet access ) and rest of the network should access .How can i do that ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which acl&amp;nbsp; from&amp;nbsp; below (1,2,3 &amp;amp;4 ) will do that ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible i can&amp;nbsp; do it in &lt;SPAN&gt;Outside_acl (2,3,&amp;amp;4 )&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dmz host&lt;/P&gt;
&lt;P&gt;172.16.10.250&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network Obj-172.16.10.250&lt;/P&gt;
&lt;P&gt;host 172.16.10.250&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-group Outside_acl in interface Outside&lt;/P&gt;
&lt;P&gt;access-group DMZ_acl in interface DMZ&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1)&lt;/P&gt;
&lt;P&gt;access-list DMZ_acl extended deny ip host 172.16.10.250 interface Outside&lt;/P&gt;
&lt;P&gt;access-list DMZ_acl extended permit ip any any&lt;/P&gt;
&lt;P&gt;access-list DMZ_acl extended deny ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2)&lt;/P&gt;
&lt;P&gt;access-list Outside_acl extended deny ip any host 172.16.10.250&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3)&lt;/P&gt;
&lt;P&gt;access-list Outside_acl extended deny ip host 172.16.10.250 any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4)&lt;/P&gt;
&lt;P&gt;access-list Outside_acl extended deny ip any object Obj-172.16.10.250&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:29:45 GMT</pubDate>
    <dc:creator>elite2010</dc:creator>
    <dc:date>2019-03-12T07:29:45Z</dc:date>
    <item>
      <title>acl on asa</title>
      <link>https://community.cisco.com/t5/network-security/acl-on-asa/m-p/2860072#M171779</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help me to understand how the acl works on asa code 9.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i want to block a host (&lt;SPAN&gt;172.16.10.250) &lt;/SPAN&gt;from dmz&amp;nbsp; zone to outside (internet access ) and rest of the network should access .How can i do that ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which acl&amp;nbsp; from&amp;nbsp; below (1,2,3 &amp;amp;4 ) will do that ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible i can&amp;nbsp; do it in &lt;SPAN&gt;Outside_acl (2,3,&amp;amp;4 )&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dmz host&lt;/P&gt;
&lt;P&gt;172.16.10.250&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network Obj-172.16.10.250&lt;/P&gt;
&lt;P&gt;host 172.16.10.250&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-group Outside_acl in interface Outside&lt;/P&gt;
&lt;P&gt;access-group DMZ_acl in interface DMZ&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1)&lt;/P&gt;
&lt;P&gt;access-list DMZ_acl extended deny ip host 172.16.10.250 interface Outside&lt;/P&gt;
&lt;P&gt;access-list DMZ_acl extended permit ip any any&lt;/P&gt;
&lt;P&gt;access-list DMZ_acl extended deny ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2)&lt;/P&gt;
&lt;P&gt;access-list Outside_acl extended deny ip any host 172.16.10.250&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3)&lt;/P&gt;
&lt;P&gt;access-list Outside_acl extended deny ip host 172.16.10.250 any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4)&lt;/P&gt;
&lt;P&gt;access-list Outside_acl extended deny ip any object Obj-172.16.10.250&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:29:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-on-asa/m-p/2860072#M171779</guid>
      <dc:creator>elite2010</dc:creator>
      <dc:date>2019-03-12T07:29:45Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/acl-on-asa/m-p/2860073#M171780</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ACL's on the 9.x code work the same as they used to work on the &lt;G class="gr_ gr_63 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="63" data-gr-id="63"&gt;prevous&lt;/G&gt; codes.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You would need the option 1 to deny access to &lt;G class="gr_ gr_100 gr-alert gr_gramm undefined Grammar multiReplace" id="100" data-gr-id="100"&gt;internet&lt;/G&gt;.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You do not need the keyword outside interface on the ACL.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;access-list DMZ_acl extended deny &lt;G class="gr_ gr_130 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="130" data-gr-id="130"&gt;ip&lt;/G&gt; host 172.16.10.250 any&lt;/P&gt;
&lt;P&gt;access-list DMZ_acl extended permit &lt;G class="gr_ gr_131 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="131" data-gr-id="131"&gt;ip&lt;/G&gt; &lt;G class="gr_ gr_142 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="142" data-gr-id="142"&gt;any any&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;access-list DMZ_acl extended deny &lt;G class="gr_ gr_132 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="132" data-gr-id="132"&gt;ip&lt;/G&gt; &lt;G class="gr_ gr_141 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="141" data-gr-id="141"&gt;any any&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also no need to add deny &lt;G class="gr_ gr_174 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="174" data-gr-id="174"&gt;ip&lt;/G&gt; &lt;G class="gr_ gr_191 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="191" data-gr-id="191"&gt;any any&lt;/G&gt; as you are already permitting &lt;G class="gr_ gr_209 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="209" data-gr-id="209"&gt;ip&lt;/G&gt;&amp;nbsp;any any in the line above it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can use a packet-tracer command to validate the rules.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input &lt;G class="gr_ gr_289 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="289" data-gr-id="289"&gt;dmz&lt;/G&gt;&amp;nbsp;&lt;G class="gr_ gr_293 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="293" data-gr-id="293"&gt;icmp&lt;/G&gt;&amp;nbsp;172.16.10.250 8 0 4.2.2.2 detailed&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You should see ACL denying the traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 06:30:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-on-asa/m-p/2860073#M171780</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-16T06:30:27Z</dc:date>
    </item>
    <item>
      <title>Thanks Adithya,</title>
      <link>https://community.cisco.com/t5/network-security/acl-on-asa/m-p/2860074#M171781</link>
      <description>&lt;P&gt;Thanks Adithya,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;" access-list DMZ_acl extended deny ip host 172.16.10.250 any"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if I put any instead of outside interface , the host wont be able to communicate inside zone also&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;correct me if &amp;nbsp;i am wrong&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 06:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-on-asa/m-p/2860074#M171781</guid>
      <dc:creator>elite2010</dc:creator>
      <dc:date>2016-03-16T06:48:03Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/acl-on-asa/m-p/2860075#M171782</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_88 gr-alert gr_gramm undefined Punctuation only-ins replaceWithoutSep" id="88" data-gr-id="88"&gt;Yes&lt;/G&gt; you are correct.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 06:53:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-on-asa/m-p/2860075#M171782</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-16T06:53:13Z</dc:date>
    </item>
  </channel>
</rss>

