<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can not get ACL work on AS Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-not-get-acl-work-on-as-firewall/m-p/4026380#M22745</link>
    <description>&lt;P&gt;Gents ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a ASA 5506 Firewall work as a transparent mood.&amp;nbsp; I am trying to add ACL to port 1 and 2 to accept only 2 specific ip address to that port.&lt;/P&gt;&lt;P&gt;this ASA have BVI interface&amp;nbsp; that assigned to PORT 1 and PORT 2 on the firewall.&lt;/P&gt;&lt;P&gt;ASA giga Port 1 must accept only device that contain ip 10.1.1.1 and ASA giga port 2 must accept only device that contain the ip&amp;nbsp; 10.1.1.2 .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both ports are on the same security level and traffic transport between same security level is enabled. ASA is not connected to internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I try to write an ACL as follows :&lt;/P&gt;&lt;P&gt;create an object&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network FBM&lt;BR /&gt;host 10.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create ACL&lt;BR /&gt;access-list BLK&amp;nbsp; extended permit ip object FBM any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-group&lt;BR /&gt;access-group BLK&amp;nbsp; in interface prod&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface:&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;bridge-group 99&lt;BR /&gt;nameif prod&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;But&amp;nbsp; when i try to connect host 10.1.1.4 to the interface 1 It let me still ping to 10.1.1.3 (BVI interface).&amp;nbsp; what i want to achieve is it should not let anything inn if the ip address is not 10.1.1.1&amp;nbsp; on port 1 .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help pls ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 09 Feb 2020 11:51:58 GMT</pubDate>
    <dc:creator>LANSK</dc:creator>
    <dc:date>2020-02-09T11:51:58Z</dc:date>
    <item>
      <title>Can not get ACL work on AS Firewall</title>
      <link>https://community.cisco.com/t5/network-security/can-not-get-acl-work-on-as-firewall/m-p/4026380#M22745</link>
      <description>&lt;P&gt;Gents ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a ASA 5506 Firewall work as a transparent mood.&amp;nbsp; I am trying to add ACL to port 1 and 2 to accept only 2 specific ip address to that port.&lt;/P&gt;&lt;P&gt;this ASA have BVI interface&amp;nbsp; that assigned to PORT 1 and PORT 2 on the firewall.&lt;/P&gt;&lt;P&gt;ASA giga Port 1 must accept only device that contain ip 10.1.1.1 and ASA giga port 2 must accept only device that contain the ip&amp;nbsp; 10.1.1.2 .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both ports are on the same security level and traffic transport between same security level is enabled. ASA is not connected to internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I try to write an ACL as follows :&lt;/P&gt;&lt;P&gt;create an object&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network FBM&lt;BR /&gt;host 10.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create ACL&lt;BR /&gt;access-list BLK&amp;nbsp; extended permit ip object FBM any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-group&lt;BR /&gt;access-group BLK&amp;nbsp; in interface prod&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface:&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;bridge-group 99&lt;BR /&gt;nameif prod&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;But&amp;nbsp; when i try to connect host 10.1.1.4 to the interface 1 It let me still ping to 10.1.1.3 (BVI interface).&amp;nbsp; what i want to achieve is it should not let anything inn if the ip address is not 10.1.1.1&amp;nbsp; on port 1 .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help pls ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 11:51:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-get-acl-work-on-as-firewall/m-p/4026380#M22745</guid>
      <dc:creator>LANSK</dc:creator>
      <dc:date>2020-02-09T11:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can not get ACL work on AS Firewall</title>
      <link>https://community.cisco.com/t5/network-security/can-not-get-acl-work-on-as-firewall/m-p/4026502#M22746</link>
      <description>&lt;P&gt;You need to deny the ICMP packets using the ICMP deny command.&lt;/P&gt;
&lt;P&gt;If you want to deny all packets on a specific interface use the following command.&lt;/P&gt;
&lt;P&gt;icmp deny 0.0.0.0 0.0.0.0 echo prod&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 21:28:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-get-acl-work-on-as-firewall/m-p/4026502#M22746</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-02-09T21:28:11Z</dc:date>
    </item>
  </channel>
</rss>

