<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,It would not be possible in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537270#M206304</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It would not be possible.&lt;/P&gt;&lt;P&gt;You would have to create separate ACE for each Subnet range.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
    <pubDate>Thu, 09 Oct 2014 05:50:59 GMT</pubDate>
    <dc:creator>Vibhor Amrodia</dc:creator>
    <dc:date>2014-10-09T05:50:59Z</dc:date>
    <item>
      <title>Discontiguous subnet mask - FWSM</title>
      <link>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537269#M206303</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I would like to permit only a few IP addresses from various subnets through an&amp;nbsp;fwsm, is there a way to summarize this in order to reduce the number of ACL rules? We have over 200 subnets all starting 10.10.&amp;lt;building&amp;gt;.0/24. I would like to only permit IPs 10.10.x.248 and above from each building. Do FWSMs allow discontiguous masks? For example, could I add a rule 10.10.0.248 / 255.255.0.248? I tried the config via ASDM and it took it but changed the format to 10.10.0.248/29 so I'm not sure whether it will allow any value in the third octet.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Amy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:53:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537269#M206303</guid>
      <dc:creator>Little Bunny</dc:creator>
      <dc:date>2019-03-12T04:53:04Z</dc:date>
    </item>
    <item>
      <title>Hi,It would not be possible</title>
      <link>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537270#M206304</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It would not be possible.&lt;/P&gt;&lt;P&gt;You would have to create separate ACE for each Subnet range.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 05:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537270#M206304</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-10-09T05:50:59Z</dc:date>
    </item>
    <item>
      <title>Hi VibhorThanks for the</title>
      <link>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537271#M206305</link>
      <description>&lt;P&gt;Hi Vibhor&lt;/P&gt;&lt;P&gt;Thanks for the feedback.&amp;nbsp;I just looked at the config via the CLI and this is the entry for the ACL:&lt;/P&gt;&lt;P&gt;access-list FWGLUE_access_in extended permit ip host 197.42.33.49 10.10.0.248 255.255.0.248&lt;/P&gt;&lt;P&gt;It looks like it took the original configuration I entered, are you sure it won't work?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Amy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 16:35:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537271#M206305</guid>
      <dc:creator>Little Bunny</dc:creator>
      <dc:date>2014-10-09T16:35:31Z</dc:date>
    </item>
    <item>
      <title>Hi Amy,Thank you for your</title>
      <link>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537272#M206306</link>
      <description>&lt;P&gt;Hi Amy,&lt;/P&gt;&lt;P&gt;Thank you for your reply. I tested it and it seems to be working for me.&lt;/P&gt;&lt;P&gt;Can you try this ACL and let me know if you face any issues.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2014 03:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537272#M206306</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-10-10T03:13:44Z</dc:date>
    </item>
    <item>
      <title>Thanks Vibhor, that sounds</title>
      <link>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537273#M206307</link>
      <description>&lt;P&gt;Thanks Vibhor, that sounds promising! I will test this out too asap &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2014 04:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discontiguous-subnet-mask-fwsm/m-p/2537273#M206307</guid>
      <dc:creator>Little Bunny</dc:creator>
      <dc:date>2014-10-10T04:14:57Z</dc:date>
    </item>
  </channel>
</rss>

