<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IOS Firewall: what is this class map doing? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-firewall-what-is-this-class-map-doing/m-p/2113474#M394976</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I think I should be setting this to &lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;match-all &lt;/STRONG&gt;and not match-any if I want it to allow the ssh protocol from only my IP, correct? &lt;/P&gt;&lt;P&gt;Exactly you are getting it now &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; It needs to be a match all....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the ACL should be like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list SSH&lt;/P&gt;&lt;P&gt;permit tcp host outside_user_ip host router_outside_interface eq 22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Nov 2012 01:33:54 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-11-29T01:33:54Z</dc:date>
    <item>
      <title>IOS Firewall: what is this class map doing?</title>
      <link>https://community.cisco.com/t5/network-security/ios-firewall-what-is-this-class-map-doing/m-p/2113473#M394975</link>
      <description>&lt;P&gt;Hi, a few weeks ago I set up a class map but now as I am finding time to review my config, I am wondering what effect this has.&amp;nbsp; It is applied to a policy map for ssh access from the Internet to the router for management: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect &lt;STRONG&gt;match-any &lt;/STRONG&gt;SSH&lt;/P&gt;&lt;P&gt;match protocol ssh&lt;/P&gt;&lt;P&gt;match access-group name SSH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access list with the name "SSH" just allows certain public IP network blocks.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I think I should be setting this to &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;match-all&lt;/STRONG&gt;&lt;/SPAN&gt; and not match-any if I want it to allow the ssh protocol from only my IP, correct?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also just to ensure I am not confused about proper creation of the ACL.&amp;nbsp; The ACL with the name SSH I've given is as follows: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended SSH&lt;/P&gt;&lt;P&gt;permit tcp xx.xx.0.0 0.255.255.255 any eq 22&lt;/P&gt;&lt;P&gt;permit tcp xx.xx.0.0 0.7.255.255 any eq 22&lt;/P&gt;&lt;P&gt;permit tcp xx.xx.0.0 0.255.255.255 any eq 22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, am I being redundant in the class map by telling it to match protocol ssh and also specifiying port 22 in the ACL? And, is this ACL readout done properly if I want only certain IP blocks to be able to come in from the Internet, to the router, using ssh?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;\&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-firewall-what-is-this-class-map-doing/m-p/2113473#M394975</guid>
      <dc:creator>cluovpemb</dc:creator>
      <dc:date>2019-03-12T00:29:39Z</dc:date>
    </item>
    <item>
      <title>IOS Firewall: what is this class map doing?</title>
      <link>https://community.cisco.com/t5/network-security/ios-firewall-what-is-this-class-map-doing/m-p/2113474#M394976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I think I should be setting this to &lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;match-all &lt;/STRONG&gt;and not match-any if I want it to allow the ssh protocol from only my IP, correct? &lt;/P&gt;&lt;P&gt;Exactly you are getting it now &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; It needs to be a match all....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the ACL should be like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list SSH&lt;/P&gt;&lt;P&gt;permit tcp host outside_user_ip host router_outside_interface eq 22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 01:33:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-firewall-what-is-this-class-map-doing/m-p/2113474#M394976</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-29T01:33:54Z</dc:date>
    </item>
    <item>
      <title>IOS Firewall: what is this class map doing?</title>
      <link>https://community.cisco.com/t5/network-security/ios-firewall-what-is-this-class-map-doing/m-p/2113475#M394977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Ok I set it to match-all.&amp;nbsp; However with the ACL, my office connection is on dynamic IP and so my ISP asigns IP in the address blocks that I've put into there.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But now for the part about the router_outside_interface.&amp;nbsp; Setting this instead of saying "any" won't have problems iwth say, VPN or NAT or whatever else?&amp;nbsp; it's simplying saying that ssh will go to the outside interface and that's that?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 17:54:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-firewall-what-is-this-class-map-doing/m-p/2113475#M394977</guid>
      <dc:creator>cluovpemb</dc:creator>
      <dc:date>2012-11-30T17:54:38Z</dc:date>
    </item>
    <item>
      <title>IOS Firewall: what is this class map doing?</title>
      <link>https://community.cisco.com/t5/network-security/ios-firewall-what-is-this-class-map-doing/m-p/2113476#M394978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So dinamic Ip address ,got it.. Then you will need to do it as you have it before...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct,as it will be from out to self&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 19:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-firewall-what-is-this-class-map-doing/m-p/2113476#M394978</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-30T19:28:18Z</dc:date>
    </item>
  </channel>
</rss>

