<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5505 Lockdown in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-lockdown/m-p/968159#M437217</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks. Ive already done the shutdown. Ill check the link (if helpfull, ill rate..)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking to ensure that if they take the phone out, they will get nowhere. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 18 May 2008 22:34:32 GMT</pubDate>
    <dc:creator>don.click1</dc:creator>
    <dc:date>2008-05-18T22:34:32Z</dc:date>
    <item>
      <title>ASA5505 Lockdown</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-lockdown/m-p/968157#M437213</link>
      <description>&lt;P&gt;Hey guys - i have a couple of questions that I hope are quick to answer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a need to provide users with a IP phone at home (extended leave, part timers, etc). The current plan is to provide them an ASA5505 that is configured to create the VPN tunnel over the internet (connects to a ASA5520). We also want to lock down the all the ports execpt e0/0 (outside interface) and e0/7 (the poe enabled phone port).  I am tring to configure 5505 so that only the phone will get an ip, AND if they remove the phone, and plug in a desktop/laptop/etc, it wont work (ie - no ip address supplied, ports blocked, etc.). The users will need to use thier existing VPN on thier laptop to get network, we are just trying to supply them a "off site extension" of thier phoens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So - Question 1 - Can I have the dhcp scope on the asa5505 defined to do a MAC based assignment? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 2 - If we cant lock down the scope by mac address, what ports, other than http and skinny (no sip phones here) would/should I block?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;If anyone has any other suggstions, im all ears.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 10:01:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-lockdown/m-p/968157#M437213</guid>
      <dc:creator>don.click1</dc:creator>
      <dc:date>2020-02-21T10:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Lockdown</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-lockdown/m-p/968158#M437215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Place a "shutdown" on interfaces e0/1 to e0/6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For control of devices by MAC access, see "mac-list" command at the following URL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/m.html#wp1888833" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/m.html#wp1888833&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 May 2008 22:30:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-lockdown/m-p/968158#M437215</guid>
      <dc:creator>samuellthomasjr</dc:creator>
      <dc:date>2008-05-18T22:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Lockdown</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-lockdown/m-p/968159#M437217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks. Ive already done the shutdown. Ill check the link (if helpfull, ill rate..)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking to ensure that if they take the phone out, they will get nowhere. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 May 2008 22:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-lockdown/m-p/968159#M437217</guid>
      <dc:creator>don.click1</dc:creator>
      <dc:date>2008-05-18T22:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Lockdown</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-lockdown/m-p/968160#M437218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have read up on the mac-list, and it seems that would work. My question now - how do I apply that to only 1 interface?  Seems to me that, since its a global command, it will restrict on all ports, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need e0/0 to be unrestricted, as I have NO idea what the mac address will be of the "dirty" side, but at the same time, e0/7 should be restricted to only the phone that I supply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for the link&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2008 16:43:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-lockdown/m-p/968160#M437218</guid>
      <dc:creator>don.click1</dc:creator>
      <dc:date>2008-05-20T16:43:41Z</dc:date>
    </item>
  </channel>
</rss>

