<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5505 firewall rule not blocking in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176548#M359018</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would seem to me that the program must use some other ports than the ones you have defined if it still gets through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you should run Wireshark on your computer or on the ASA to see what connections the host computer actually forms when Mumble is used. And use that information to update the "deny" rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Apr 2013 12:15:46 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-04-03T12:15:46Z</dc:date>
    <item>
      <title>ASA5505 firewall rule not blocking</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176544#M359013</link>
      <description>&lt;P&gt;I'm trying to troubleshoot an ASA5505.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The original goal was to block "Mumble/Murmur" (a voip app) traffic, which runs on TCP/UDP 64738, both inbound and outbound, except to a certain host (63.223.117.170).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when nothing I tried seemed to make a difference, just to troubleshoot, I decided to try blocking all inbound traffic.&amp;nbsp; I first disconnected ethernet port 0/0 to ensure that it was cabled correctly and the outside interface went down when I did.&amp;nbsp; That worked as expected, so I confirmed I had the right interface and it was cabled correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then applied a "any any deny ip" rule as the first element in the outside interface access_list, as you can see below.&amp;nbsp; However, it appears to have had no real effect and the hit count is very low (it should be astronomical).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me why such a deny any any rule would not be taking effect?&amp;nbsp; I'm sure I'm missing something simple, but whatever it is is escaping me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show ver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.0(2)&lt;/P&gt;&lt;P&gt;Device Manager Version 7.1(2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Thu 21-Feb-13 13:10 by builders&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa902-k8.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show switch vlan&lt;/P&gt;&lt;P&gt;VLAN Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status&amp;nbsp;&amp;nbsp;&amp;nbsp; Ports&lt;/P&gt;&lt;P&gt;---- -------------------------------- --------- -----------------------------&lt;/P&gt;&lt;P&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp; inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Et0/1, Et0/2, Et0/3, Et0/4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Et0/6, Et0/7&lt;/P&gt;&lt;P&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Et0/0&lt;/P&gt;&lt;P&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp; dmz&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Et0/5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; description outside&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; description inside&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address dhcp setroute&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; description DMZ&lt;/P&gt;&lt;P&gt; nameif dmz&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 10.1.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network mc_server&lt;/P&gt;&lt;P&gt; host 63.223.117.170&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service Mumble tcp-udp&lt;/P&gt;&lt;P&gt; description Mumble VOIP protocol&lt;/P&gt;&lt;P&gt; port-object eq 64738&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any4 any4 echo-reply&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any4 object webserver_smtp eq smtp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any4 object webserver_smtp object-group DM_INLINE_TCP_1&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any4 object webserver_ssh_host eq ssh&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object xbox_udp_88 any4 object xbox_port_88&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object xbox_tcp_3074 any4 object xbox_tcp_port_3074&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object xbox_udp_3074 any4 object xbox_udp_port_3074&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any4 object Tower_SSH eq ssh&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any4 object xbox&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip object mc_server any&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny object-group TCPUDP any any4 object-group Mumble&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz,outside) after-auto source dynamic obj_any interface&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group dmz in interface dmz&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 01:04:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176544#M359013</guid>
      <dc:creator>wwilliam</dc:creator>
      <dc:date>2019-03-13T01:04:58Z</dc:date>
    </item>
    <item>
      <title>ASA5505 firewall rule not blocking</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176545#M359014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Wade,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So are you telling that traffic is being accepted?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 06:07:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176545#M359014</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-03T06:07:54Z</dc:date>
    </item>
    <item>
      <title>ASA5505 firewall rule not blocking</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176546#M359016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the Mumble is anything like Teamspeak I would imagine that the hosts application connects to a remote server and there isnt actually connections taken from "outside" to "inside".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried blocking this in the "inside" ACL so that the connections are never allowed to form through the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewall allows the user to form the connection through once then the return traffic is allowed automatically (for that same connection that is) and the "outside" ACL will not be applied to that traffic as it has already been allowed by the "inside" ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 06:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176546#M359016</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-03T06:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 firewall rule not blocking</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176547#M359017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;JouniForss wrote:&lt;/P&gt;&lt;P&gt;Have you tried blocking this in the "inside" ACL so that the connections are never allowed to form through the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewall allows the user to form the connection through once then the return traffic is allowed automatically (for that same connection that is) and the "outside" ACL will not be applied to that traffic as it has already been allowed by the "inside" ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Agreed.&amp;nbsp; I do have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in remark Allow mumble traffic only to our own server&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit object-group TCPUDP any object mc_server object-group Mumble&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny object-group TCPUDP any any object-group Mumble&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In doing some more testing though, it appears the answer is it will be nearly impossible to block.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It connects to a web server to determine the IP addresses of available servers.&amp;nbsp; It then establishes a connection with that server.&amp;nbsp; The server may be running on any port.&amp;nbsp; Using the information it learns from the web server, the client opens TCP and UDP connections.&amp;nbsp; But, since there's no guarantee what port(s) will be used, the only solution is to block access to the web server, which blocks access to all servers.&amp;nbsp; I was attempting to block access to all but one, but it appears that's not possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 12:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176547#M359017</guid>
      <dc:creator>wwilliam</dc:creator>
      <dc:date>2013-04-03T12:10:41Z</dc:date>
    </item>
    <item>
      <title>ASA5505 firewall rule not blocking</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176548#M359018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would seem to me that the program must use some other ports than the ones you have defined if it still gets through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you should run Wireshark on your computer or on the ASA to see what connections the host computer actually forms when Mumble is used. And use that information to update the "deny" rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 12:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-firewall-rule-not-blocking/m-p/2176548#M359018</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-03T12:15:46Z</dc:date>
    </item>
  </channel>
</rss>

