<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You can create an based on in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737435#M178178</link>
    <description>&lt;P&gt;You can create an based on your security requirement and apply it on different interfaces, this would allow you to reuse same ACL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!!&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2015 12:58:27 GMT</pubDate>
    <dc:creator>Rishabh Seth</dc:creator>
    <dc:date>2015-10-08T12:58:27Z</dc:date>
    <item>
      <title>Beginner ACL Questing regarding Internet only access</title>
      <link>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737428#M178157</link>
      <description>&lt;P&gt;Hey Cisco Folks!&lt;/P&gt;&lt;P&gt;first, forgive me i'm a absolut ASA beginner &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; - Worked with Stonesoft and PFsense before.&lt;/P&gt;&lt;P&gt;Follow scenario:&lt;/P&gt;&lt;P&gt;Inside-Interface on a ASA-5585-X with latest OS&amp;nbsp;has some ACL's defined to DMZ, other MPLS networks and so on.&lt;BR /&gt;Default Internet Access is solved by passing all 80/443 Traffic to a Squid Proxy (Not transparent)&lt;BR /&gt;Now i have the requirement to let traffic pass the Inside LAN in direction to&amp;nbsp;Outside but only Skype.&lt;/P&gt;&lt;P&gt;I saw a lot options but no option was like a "Source Inside Destination Internet Service Any"&lt;/P&gt;&lt;P&gt;Is it really true that i have to setup this complicated?&lt;/P&gt;&lt;P&gt;-Inside-Interface-&lt;BR /&gt;Allow DMZ Stuff and so an&lt;BR /&gt;Deny Management Stuff (Hopefully don't forget some other stuff....)&lt;BR /&gt;Allow dest any service any&lt;/P&gt;&lt;P&gt;And let the Firepower Processor do the rest, e.g. let the Sourcefire detect Skype and allow it and rest deny?!&lt;/P&gt;&lt;P&gt;Why is there no&amp;nbsp;possibility to let only traffic in direction to internet pass? With Stonesoft there was a auto generated "Not Local Protected" Object and on PFSense i can let traffic flow to a interface directly. Or do i miss understand all and there is a easy what to get this on a device (2 ASA Failover pairs) which costs&amp;nbsp;&amp;gt;120k $&lt;/P&gt;&lt;P&gt;Really thanks for your input!&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737428#M178157</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-03-12T06:43:01Z</dc:date>
    </item>
    <item>
      <title>Hi,On ASA there are different</title>
      <link>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737429#M178159</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;On ASA there are different ways by which you can achieve access control. You can use combinations of IP, Ports to permit/ deny traffic. With the addition of FirePOWER services you have more granular control over your traffic.&lt;/P&gt;&lt;P&gt;Now applications such as skype can hop ports and it difficult to block with just layer 3-4 information.&lt;/P&gt;&lt;P&gt;Here application identification of FirePOWER can help in identifying the application and then apply the action that you want to take.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On ASA you create Policy-maps to redirect traffic for inspection by services module (FirePOWER).&lt;/P&gt;&lt;P&gt;Based on your requirement you can create class-maps to filter traffic which should be sent for inspection by FirePOWER or not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 12:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737429#M178159</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-08T12:16:44Z</dc:date>
    </item>
    <item>
      <title>Hi, thanks for your reply.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737430#M178161</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;for your reply. Thats already done, the firepower is configured to let Skype traffic trough. But my question was, how can i accomplish to let only traffic flow to the internet interface but to no other interface. The "dest any service any" is the only way i can see from ASA side... which is ugly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 12:26:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737430#M178161</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2015-10-08T12:26:32Z</dc:date>
    </item>
    <item>
      <title>The traffic flow on ASA is:</title>
      <link>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737431#M178164</link>
      <description>&lt;P&gt;The traffic flow on ASA is:&amp;nbsp;&lt;/P&gt;&lt;P&gt;ACL on ingress interface&amp;gt;&amp;gt;&amp;gt; Policies on FirePOWER &amp;gt;&amp;gt;&amp;gt; Policies on egress interface.&lt;/P&gt;&lt;P&gt;Once the traffic is permitted by the FirePOWER device, the egress interface will be decided by the ASA based on route/static NAT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So when you say "dest any service any" are you talking about ACL on egress interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 12:33:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737431#M178164</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-08T12:33:24Z</dc:date>
    </item>
    <item>
      <title>Thats correct but did not</title>
      <link>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737432#M178168</link>
      <description>&lt;P&gt;Thats correct but did not answer my question &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;How would you let traffic from Inside flow _only_&amp;nbsp;to Outside when you have a lot other interfaces (DMZ, Partner and so on) which have the same or higher security level and ACL's on it.&lt;/P&gt;&lt;P&gt;Or let me ask you the other way, why is a Interface Security Level obsolete as soon as there is a ACL on it? If i define dest any service any on a interface with lets say security level 50, this ACL allows to get higher up to level 100 interfaces.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 12:40:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737432#M178168</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2015-10-08T12:40:01Z</dc:date>
    </item>
    <item>
      <title>So you can use combination of</title>
      <link>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737433#M178171</link>
      <description>&lt;P&gt;So you can use combination of ACLs on ingress and egress interfaces to achieve the your requirement.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Say you want to control traffic from A (at security level50) to B(at security level100). By default lower to higher security level will be blocked but when you use ACL then it would take precedence.&lt;/P&gt;&lt;P&gt;Now to control traffic from A to B you can apply ACL in out direction on interface B.&lt;/P&gt;&lt;P&gt;Hope it helps!!!.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 12:51:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737433#M178171</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-08T12:51:13Z</dc:date>
    </item>
    <item>
      <title>Understood. There is also no</title>
      <link>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737434#M178175</link>
      <description>&lt;P&gt;Understood. There is also no easier way to let traffic flow from inside to outside only... well thats a real pity &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;Thanks for your time!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 12:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737434#M178175</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2015-10-08T12:56:00Z</dc:date>
    </item>
    <item>
      <title>You can create an based on</title>
      <link>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737435#M178178</link>
      <description>&lt;P&gt;You can create an based on your security requirement and apply it on different interfaces, this would allow you to reuse same ACL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!!&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 12:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-acl-questing-regarding-internet-only-access/m-p/2737435#M178178</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-08T12:58:27Z</dc:date>
    </item>
  </channel>
</rss>

