<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic identify ports between PCs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/identify-ports-between-pcs/m-p/2704433#M193507</link>
    <description>&lt;P&gt;Hello Guys&lt;/P&gt;&lt;P&gt;I need to identify ports between two PCs so that I can lock them down via ACL on ASA5512-x, the problem is how do I know what ports should be allowed and what should be denied?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am aware of 'netstat', but does it mean every single port on netstat needs to be opened?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:18:48 GMT</pubDate>
    <dc:creator>LionKin1984</dc:creator>
    <dc:date>2019-03-12T06:18:48Z</dc:date>
    <item>
      <title>identify ports between PCs</title>
      <link>https://community.cisco.com/t5/network-security/identify-ports-between-pcs/m-p/2704433#M193507</link>
      <description>&lt;P&gt;Hello Guys&lt;/P&gt;&lt;P&gt;I need to identify ports between two PCs so that I can lock them down via ACL on ASA5512-x, the problem is how do I know what ports should be allowed and what should be denied?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am aware of 'netstat', but does it mean every single port on netstat needs to be opened?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identify-ports-between-pcs/m-p/2704433#M193507</guid>
      <dc:creator>LionKin1984</dc:creator>
      <dc:date>2019-03-12T06:18:48Z</dc:date>
    </item>
    <item>
      <title>Your application-support-team</title>
      <link>https://community.cisco.com/t5/network-security/identify-ports-between-pcs/m-p/2704434#M193510</link>
      <description>&lt;P&gt;Your application-support-team should be able to tell you which ports the PCs need. In reality, they typically don't know.&lt;/P&gt;&lt;P&gt;One way to find out is to start with a "deny ip any any" and wait for the complains. Then add the needed ACEs for communication that is desired.&lt;/P&gt;&lt;P&gt;Or start with an ACL that allows all, but also logs the traffic. There you can identify was is done by the PC, and allow all that is needed. After some time you just remove the last "permit ip any any"-line.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2015 08:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identify-ports-between-pcs/m-p/2704434#M193510</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-07-22T08:06:24Z</dc:date>
    </item>
    <item>
      <title>Thanks for your reply Karsten</title>
      <link>https://community.cisco.com/t5/network-security/identify-ports-between-pcs/m-p/2704435#M193511</link>
      <description>&lt;P&gt;Thanks for your reply Karsten, allow any any and log sounds like a brilliant idea, I ll try that&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2015 08:11:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identify-ports-between-pcs/m-p/2704435#M193511</guid>
      <dc:creator>LionKin1984</dc:creator>
      <dc:date>2015-07-22T08:11:19Z</dc:date>
    </item>
  </channel>
</rss>

