<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Simple ACL outside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344151#M343281</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah, you could also try to use reflexive ACLs but that's certanly not as scalable as the ZBFW option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Sep 2013 19:26:39 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-09-10T19:26:39Z</dc:date>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344142#M343272</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does a router require a Firewall license in order to apply an ACL in the inward direction on an outside interface?&amp;nbsp; I have a router which I use to NAT our internal network and I want to apply a simple ACL to block unwanted access to the router from the internet.&amp;nbsp; As soon as this ACL is applied the users cannot browse the internet.&amp;nbsp; I do have a couple of other ISR routers with a firewall license and I use the inspect commands.&amp;nbsp; This is an ASR which may be different, but I do not have the firewall license applied to this router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344142#M343272</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2019-03-12T02:35:57Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344143#M343273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No need for the ACL,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can provide us the configuration and then we will analize it for you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 21:38:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344143#M343273</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-09-09T21:38:20Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344144#M343274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, so what do you use to secure the router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is nothing notable about the config.&amp;nbsp; Inside interface, outside interface and nat in between.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0/0&lt;/P&gt;&lt;P&gt; description Outside Interface&lt;/P&gt;&lt;P&gt; ip address 64.64.20.64 255.255.255.128 secondary&lt;/P&gt;&lt;P&gt; ip address 37.7.7.8 255.255.255.252&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; negotiation auto&lt;/P&gt;&lt;P&gt; cdp enable&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0/1&lt;/P&gt;&lt;P&gt; description Inside Interface&lt;/P&gt;&lt;P&gt; ip address 10.110.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; negotiation auto&lt;/P&gt;&lt;P&gt; cdp enable&lt;/P&gt;&lt;P&gt; no ip virtual-reassembly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat pool pool-159.1 64.64.20.64 64.64.20.64 netmask 255.255.255.128&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ip nat inside source list ip-nat-159.1 pool pool-159.1 overload&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 14:39:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344144#M343274</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2013-09-10T14:39:59Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344145#M343275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I meant no need for a license in order to use ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share the configuration you have when the issue happens?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 15:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344145#M343275</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-09-10T15:58:53Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344146#M343276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;either you use CBAC with the inspect commands and an inbound ACL on the WAN interface or you can use ZBF(zone Based Firewall) and in this case you don't need any ACL inbound on the WAN interface.&lt;/P&gt;&lt;P&gt;Can you tell us which ISR you've got so we can tell you which IOS/licence you need for the firewall feature(CBAC or ZBF).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 16:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344146#M343276</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2013-09-10T16:00:09Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344147#M343277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah ok, then I belive I must do some troubleshooting with the ACL then.&amp;nbsp; I'm sure I am blocking something that is needed.&amp;nbsp; I am basically denying everything except the traffic from our ISP for our BGP peer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10 permit ip 64.64.0.0 0.0.255.255 any (8866 matches)&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;30 permit udp any any eq ntp (4916 matches)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;40 permit icmp any any echo-reply (9685 matches)&lt;/P&gt;&lt;P&gt;50 permit udp any any eq domain (477 matches)&lt;/P&gt;&lt;P&gt;60 permit tcp any any eq domain (13 matches)&lt;/P&gt;&lt;P&gt;1000 deny ip any any log (49238 matches)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 19:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344147#M343277</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2013-09-10T19:00:36Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344148#M343278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its not an ISR its and ASR as posted on the first post.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 19:01:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344148#M343278</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2013-09-10T19:01:10Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344149#M343279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The thing is that with the configuration you are denying HTTP , HTTPs, FTP, etc ,etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that what you are looking for, cause with that you will not allow access to any website.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My recomendation would be to use an inspection engine such as ZBFW that allows you to protect the internal network from outside users while still allowing all traffic from Inside to Outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 19:09:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344149#M343279</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-09-10T19:09:15Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344150#M343280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I agree, unfortunetly that would requre a license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 19:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344150#M343280</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2013-09-10T19:22:46Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344151#M343281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah, you could also try to use reflexive ACLs but that's certanly not as scalable as the ZBFW option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 19:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344151#M343281</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-09-10T19:26:39Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344152#M343282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very interesting.&amp;nbsp; I will look into this some more.&amp;nbsp; As far as not being as scalable are there certain gotcha's with these ACl's?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 19:36:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344152#M343282</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2013-09-10T19:36:01Z</dc:date>
    </item>
    <item>
      <title>Simple ACL outside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344153#M343283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like reflexive acl's are also not an option without a license.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2013 02:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-acl-outside-interface/m-p/2344153#M343283</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2013-09-11T02:26:49Z</dc:date>
    </item>
  </channel>
</rss>

