<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cbac set-up in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954481#M435835</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, so you would like access initiated from the Internet towards your hosts/servers on all those ports listed in access-list 121?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 26 May 2012 12:24:59 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2012-05-26T12:24:59Z</dc:date>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954478#M435830</link>
      <description>&lt;P&gt;Can I confirm with someone if that config of cbac will work:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/8/0/1/90108-router.png" alt="router.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:11:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954478#M435830</guid>
      <dc:creator>mateomateo1</dc:creator>
      <dc:date>2019-03-11T23:11:38Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954479#M435832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you trying to allow inbound or outbound access on your access-list 121? From what i read, it seems more for outbound than inbound access, please kindly confirm.&lt;/P&gt;&lt;P&gt;If it's for outbound access, you would either need to apply the access-list on the LAN interface (in direction), or on the WAN interface (out direction).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 May 2012 00:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954479#M435832</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-05-26T00:39:40Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954480#M435834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 121 is for inbound access (from internet)&lt;/P&gt;&lt;P&gt; - access-group 121 in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;inspect rule is applied on the same interface outbound&lt;/P&gt;&lt;P&gt;-ip inspect myfw out&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 May 2012 07:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954480#M435834</guid>
      <dc:creator>mateomateo1</dc:creator>
      <dc:date>2012-05-26T07:56:54Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954481#M435835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, so you would like access initiated from the Internet towards your hosts/servers on all those ports listed in access-list 121?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 May 2012 12:24:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954481#M435835</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-05-26T12:24:59Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954482#M435836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; correct Jennifer access to those servers from acl 121 + alow all access from inside lan to the internet (with cbac)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 May 2012 18:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954482#M435836</guid>
      <dc:creator>mateomateo1</dc:creator>
      <dc:date>2012-05-26T18:46:18Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954483#M435837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok thanks for confirming.&lt;/P&gt;&lt;P&gt;In that case, they all look good to me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 May 2012 19:34:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954483#M435837</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-05-26T19:34:19Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954484#M435838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you Jennifer for confirming, &lt;/P&gt;&lt;P&gt;I have also another question about my second wan interface, I have 2 isp, wan2 is my vpn connection to branch office and&amp;nbsp; wan1 is my internet access (with cbac on it - that is sorted now), now after wan1 is sorted I want also some sort of security on my vpn connection, what would be the best way to secure that connection, can I just apply&lt;/P&gt;&lt;P&gt;something like that on both sides ?&lt;/P&gt;&lt;P&gt;access-list 122 permit ip LAN1 LAN2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/3/2/90230-Untitled.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 May 2012 08:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954484#M435838</guid>
      <dc:creator>mateomateo1</dc:creator>
      <dc:date>2012-05-28T08:18:48Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954485#M435839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With access-list 122, you just have to permit the actual VPN traffic before decryption as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 122 permit esp host &lt;REMOTE-VPN-SERVER&gt; host &lt;WAN2-IP-ADDRESS&gt;&lt;/WAN2-IP-ADDRESS&gt;&lt;/REMOTE-VPN-SERVER&gt;&lt;/P&gt;&lt;P&gt;access-list 122 permit udp host &lt;REMOTE-VPN-SERVER&gt; host &lt;WAN2-IP-ADDRESS&gt; eq 500&lt;/WAN2-IP-ADDRESS&gt;&lt;/REMOTE-VPN-SERVER&gt;&lt;/P&gt;&lt;P&gt;access-list 122 permit udp host &lt;REMOTE-VPN-SERVER&gt; host &lt;WAN2-IP-ADDRESS&gt; eq 4500&lt;/WAN2-IP-ADDRESS&gt;&lt;/REMOTE-VPN-SERVER&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 May 2012 11:29:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954485#M435839</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-05-28T11:29:47Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954486#M435840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would it be the best way of securing the router (interfaces) with the firewall?&amp;nbsp; What can be done to secure it,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2012 09:24:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954486#M435840</guid>
      <dc:creator>mateomateo1</dc:creator>
      <dc:date>2012-06-07T09:24:41Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954487#M435841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CBAC is one way to secure it, or you can also use ZBFW (Zone Base FW).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2012 10:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954487#M435841</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-07T10:08:21Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954488#M435843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you Jennifer for all the answers, as regards to my firewall on vpn link (only acl) is that enough security?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2012 10:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954488#M435843</guid>
      <dc:creator>mateomateo1</dc:creator>
      <dc:date>2012-06-07T10:42:56Z</dc:date>
    </item>
    <item>
      <title>cbac set-up</title>
      <link>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954489#M435845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that would be good enough as only IPSec VPN is allowed, and no other protocols.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2012 11:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-set-up/m-p/1954489#M435845</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-07T11:02:56Z</dc:date>
    </item>
  </channel>
</rss>

