<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5520 can't block incomming traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-can-t-block-incomming-traffic/m-p/2099660#M394125</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you try to limit access to the ASA inside interface itself just from a specific IP Address?&lt;/P&gt;&lt;P&gt;How are you trying to access the inside interface? SSH? HTTP? Ping?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-list applied to the inside interface is configured for traffic going through the firewall, eg: from inside network to internet, not for traffic towards the ASA interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are trying to limit access to the ASA interface itself, then you should be using the ssh, http, or icmp command to only allow access to specific IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Dec 2012 04:48:50 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2012-12-14T04:48:50Z</dc:date>
    <item>
      <title>ASA 5520 can't block incomming traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-can-t-block-incomming-traffic/m-p/2099659#M394124</link>
      <description>&lt;P&gt;I was configure 3 interface on ASA&lt;/P&gt;&lt;P&gt;1st - managemetn (only for management)&lt;/P&gt;&lt;P&gt;2nd - gig0/0 is connected to internet with real IP&lt;/P&gt;&lt;P&gt;3rd - gig0/1 is connected to local network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was configure routed NAT to internet.&lt;/P&gt;&lt;P&gt;But I have problem with restriction incomming traffic to inside interface (ifname is inside)&lt;/P&gt;&lt;P&gt;I was create access lists &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;access-list INSIDE_IN extended permit ip object-group ADMIN any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list INSIDE_IN extended deny ip any any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;And link access list to inside interface by rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;access-group INSIDE_IN in interface inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; but I can connect to ip address of inside interface from other ip. It is wrong and i can't understand where is my mistake.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please help me anybody.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:37:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-can-t-block-incomming-traffic/m-p/2099659#M394124</guid>
      <dc:creator>Nikolay Savin</dc:creator>
      <dc:date>2019-03-12T00:37:08Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 can't block incomming traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-can-t-block-incomming-traffic/m-p/2099660#M394125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you try to limit access to the ASA inside interface itself just from a specific IP Address?&lt;/P&gt;&lt;P&gt;How are you trying to access the inside interface? SSH? HTTP? Ping?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-list applied to the inside interface is configured for traffic going through the firewall, eg: from inside network to internet, not for traffic towards the ASA interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are trying to limit access to the ASA interface itself, then you should be using the ssh, http, or icmp command to only allow access to specific IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2012 04:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-can-t-block-incomming-traffic/m-p/2099660#M394125</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-12-14T04:48:50Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 can't block incomming traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-can-t-block-incomming-traffic/m-p/2099661#M394126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now all is clear.&lt;/P&gt;&lt;P&gt;I has been doubt in the question how access-lists is working with traffic going towards the ASA interface.&lt;/P&gt;&lt;P&gt;Thank You for responce&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2012 05:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-can-t-block-incomming-traffic/m-p/2099661#M394126</guid>
      <dc:creator>Nikolay Savin</dc:creator>
      <dc:date>2012-12-14T05:26:13Z</dc:date>
    </item>
  </channel>
</rss>

