<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA 5510 CLI configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642488#M196054</link>
    <description>&lt;P&gt;Hello I am trying to create an object with a public IP address as a host and allow multiple udp ports to that host but cannot fine to seem the relevant documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i create the object and try the service command under it does not allow me to put in udp/tcp protocol options.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any one can advise on how to configure this please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;device details&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PID: ASA5510&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa842-k8.bin"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you need any more details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:38:45 GMT</pubDate>
    <dc:creator>Kaushik Ray</dc:creator>
    <dc:date>2019-03-12T05:38:45Z</dc:date>
    <item>
      <title>Cisco ASA 5510 CLI configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642488#M196054</link>
      <description>&lt;P&gt;Hello I am trying to create an object with a public IP address as a host and allow multiple udp ports to that host but cannot fine to seem the relevant documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i create the object and try the service command under it does not allow me to put in udp/tcp protocol options.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any one can advise on how to configure this please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;device details&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PID: ASA5510&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa842-k8.bin"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you need any more details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:38:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642488#M196054</guid>
      <dc:creator>Kaushik Ray</dc:creator>
      <dc:date>2019-03-12T05:38:45Z</dc:date>
    </item>
    <item>
      <title>Hi Kaushik,This is how you</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642489#M196055</link>
      <description>&lt;P&gt;Hi Kaushik,&lt;/P&gt;&lt;P&gt;This is how you define the object service:&lt;/P&gt;&lt;P&gt;object service test-list&lt;/P&gt;&lt;P&gt;service tcp source eq 8014&lt;/P&gt;&lt;P&gt;And below are the options. You cannot define all three of the below ports in one service. You can define range or equal or greater than etc.&lt;/P&gt;&lt;P&gt;ASA5585-2(config-service-object)# service tcp source ?&lt;/P&gt;&lt;P&gt;service-object mode commands/options:&lt;/P&gt;&lt;P&gt;&amp;nbsp; eq&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port equal to operator&lt;/P&gt;&lt;P&gt;&amp;nbsp; gt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port greater than&amp;nbsp; operator&lt;/P&gt;&lt;P&gt;&amp;nbsp; lt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port less than operator&lt;/P&gt;&lt;P&gt;&amp;nbsp; neq&amp;nbsp;&amp;nbsp;&amp;nbsp; Port not equal to operator&lt;/P&gt;&lt;P&gt;&amp;nbsp; range&amp;nbsp; Port range operator&lt;/P&gt;&lt;P&gt;Then you can use this object service in access-list or NAT rule.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2015 14:21:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642489#M196055</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-03-16T14:21:50Z</dc:date>
    </item>
    <item>
      <title>thanks I have setup something</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642490#M196056</link>
      <description>&lt;P&gt;thanks I have setup something like this. is it fine or i need to amend something ?&lt;/P&gt;&lt;P&gt;Please let me know thanks&lt;/P&gt;&lt;P&gt;object network obj-Test&lt;BR /&gt;&amp;nbsp;host xxx.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object network obj-Test&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static xxx.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit ip host yyy.yyy.yyy.yyy host xxx.xxx.xxx.xxx&lt;BR /&gt;access-list outside_acl extended permit ip host aaa.aaa.aaa.aaa host xxx.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit udp any host xxx.xxx.xxx.xxx range 20000 24000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2015 14:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642490#M196056</guid>
      <dc:creator>Kaushik Ray</dc:creator>
      <dc:date>2015-03-16T14:34:56Z</dc:date>
    </item>
    <item>
      <title>Hi Kaushik,I am not sure</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642491#M196057</link>
      <description>&lt;P&gt;Hi Kaushik,&lt;/P&gt;&lt;P&gt;I am not sure about your requirement but this command should allow udp access for the host and range you have mentioned.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2015 22:07:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642491#M196057</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-03-16T22:07:47Z</dc:date>
    </item>
    <item>
      <title>Thanks Kanwal for your reply;</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642492#M196058</link>
      <description>&lt;P&gt;Thanks Kanwal for your reply; one more thing i wanted to ask ; my host has been assigned a public ip address itself; in that case am i correct in doing a static nat to itself &amp;nbsp;or that could cause issues?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2015 23:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642492#M196058</guid>
      <dc:creator>Kaushik Ray</dc:creator>
      <dc:date>2015-03-16T23:41:11Z</dc:date>
    </item>
    <item>
      <title>Hi Kaushik,Yeah it should be</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642493#M196059</link>
      <description>&lt;P&gt;Hi Kaushik,&lt;/P&gt;&lt;P&gt;Yeah it should be fine if it is not natted anywhere else.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2015 14:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cli-configuration/m-p/2642493#M196059</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-03-18T14:27:03Z</dc:date>
    </item>
  </channel>
</rss>

