<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5500 series MAC address Access Rule Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396362#M271073</link>
    <description>&lt;P&gt;Hi all:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I went through ASA documentation, there is "mac-list" configuration command to configure mac address access list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer to the link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_fwaaa.html" rel="nofollow" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_fwaaa.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;under the topic of "Using MAC Addresses to Exempt Traffic from Authentication and Authorization".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems like the MAC Address configured is used for Authentication and Authorization exemption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, my main purpose is to configure MAC address access rule and apply to ASA 5500 series firewall. As such, I have questions below and need anybody know about MAC Address access rules on ASA 5500 series can help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Can the above MAC Address command&amp;nbsp; &lt;EM&gt;mac-list &lt;/EM&gt;can be used to configure MAC Address list and apply in the firewall interface as same as IP address, like "access-group &lt;EM&gt;mac-list &lt;/EM&gt;in interface outside"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. When the firewall in routed mode, Can the MAC Address access list and rule applying be used and how to configure to use?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. If firewall only in transparent mode then can to do the MAC Address access list and rule applying, then how to do the configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;tangsuan&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:34:07 GMT</pubDate>
    <dc:creator>Tang-Suan Tan</dc:creator>
    <dc:date>2019-03-12T03:34:07Z</dc:date>
    <item>
      <title>ASA5500 series MAC address Access Rule Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396362#M271073</link>
      <description>&lt;P&gt;Hi all:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I went through ASA documentation, there is "mac-list" configuration command to configure mac address access list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer to the link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_fwaaa.html" rel="nofollow" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_fwaaa.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;under the topic of "Using MAC Addresses to Exempt Traffic from Authentication and Authorization".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems like the MAC Address configured is used for Authentication and Authorization exemption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, my main purpose is to configure MAC address access rule and apply to ASA 5500 series firewall. As such, I have questions below and need anybody know about MAC Address access rules on ASA 5500 series can help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Can the above MAC Address command&amp;nbsp; &lt;EM&gt;mac-list &lt;/EM&gt;can be used to configure MAC Address list and apply in the firewall interface as same as IP address, like "access-group &lt;EM&gt;mac-list &lt;/EM&gt;in interface outside"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. When the firewall in routed mode, Can the MAC Address access list and rule applying be used and how to configure to use?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. If firewall only in transparent mode then can to do the MAC Address access list and rule applying, then how to do the configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;tangsuan&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:34:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396362#M271073</guid>
      <dc:creator>Tang-Suan Tan</dc:creator>
      <dc:date>2019-03-12T03:34:07Z</dc:date>
    </item>
    <item>
      <title>ASA5500 series MAC address Access Rule Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396363#M271079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The mac-list can only be used for AAA.&lt;/P&gt;&lt;P&gt;The ASA cannot block by mac address in router mode.&lt;/P&gt;&lt;P&gt;In transparent mode I think the only option is ethertype ACLs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/command-reference/a1.html#wp1598101"&gt;http://www.cisco.com/en/US/docs/security/asa/command-reference/a1.html#wp1598101&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Felipe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Remember to rate useful posts. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2014 00:48:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396363#M271079</guid>
      <dc:creator>lcambron</dc:creator>
      <dc:date>2014-01-24T00:48:23Z</dc:date>
    </item>
    <item>
      <title>ASA5500 series MAC address Access Rule Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396364#M271084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Felipe:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to your reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I refer to the link you provided, for example, if I want to allow only MAC address of a host 00-10-18-18-c3-32 (MAC address is a 12 bits Hexadecimal) from Outside to Inside, can below two CLI work? Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(config)#access-list MAC1 ethertype permit 0x00101818c332 any&lt;/P&gt;&lt;P&gt;(config)#access-group MAC1 in interface Outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tangsuan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2014 08:59:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396364#M271084</guid>
      <dc:creator>Tang-Suan Tan</dc:creator>
      <dc:date>2014-01-24T08:59:57Z</dc:date>
    </item>
    <item>
      <title>ASA5500 series MAC address Access Rule Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396365#M271092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doing more research on this, seems like the ethertype ACL cannot be use to allow or deny traffic based on MAC address.&lt;/P&gt;&lt;P&gt;So I dont think this is possible on the ASA using either routed or transparent mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Felipe. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2014 14:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396365#M271092</guid>
      <dc:creator>lcambron</dc:creator>
      <dc:date>2014-01-24T14:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5500 series MAC address Access Rule Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396366#M271097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Hi Felipe and all:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;Thanks to your reply!&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;Just think of one way to do the MAC address access control in Transparent firewall may be is by using ARP and ARP-INSPECTION. &lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;By using these two commands to match IP to a MAC Address so that that IP can act on behalf of that particular MAC Address for the purpose of configuration of IP Address access rule.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;Is it this is an alternative way of doing MAC Address access control? Anybody can advise or suggest any way? Thanks!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;On the way of trying the Transparent Firewall, I found one question here and need some advise.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;There is multiple BVI interfaces in different IP subnets can be set in the Transparent Firewall. The problem is Transparent Firewall always implements in one subnet. Then what is the purpose of doing multiple BVI in a Transparent Firewall, can anybody help to explain the purpose? Many thanks!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;tangsuan&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Jan 2014 13:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396366#M271097</guid>
      <dc:creator>Tang-Suan Tan</dc:creator>
      <dc:date>2014-01-26T13:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5500 series MAC address Access Rule Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396367#M271102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems like no reply on my above discussion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anybody please raise any point and any advice if you have on above discussion. Many thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;tangsuan &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Feb 2014 04:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5500-series-mac-address-access-rule-configuration/m-p/2396367#M271102</guid>
      <dc:creator>Tang-Suan Tan</dc:creator>
      <dc:date>2014-02-05T04:50:42Z</dc:date>
    </item>
  </channel>
</rss>

