<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA accepts non existing subnetmask in ACL in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-accepts-non-existing-subnetmask-in-acl/m-p/1981796#M440799</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, those are incorrect mask, and ASA does not check whether the subnet mask has been correctly configured or not. It is simply just a user misconfiguration if incorrect mask has been entered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Jun 2012 13:29:37 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2012-06-15T13:29:37Z</dc:date>
    <item>
      <title>ASA accepts non existing subnetmask in ACL</title>
      <link>https://community.cisco.com/t5/network-security/asa-accepts-non-existing-subnetmask-in-acl/m-p/1981795#M440798</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm configuring a l2l tunnel.&lt;/P&gt;&lt;P&gt;While configuring the crypo acl I noticed that my ASA was accepting subnetmasks like 255.255.255.1 (wich does not exist to my knowledge).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then tried some other masks, and to my surprise it accepted almost everyting?!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_30 extended permit ip 192.168.1.0 255.255.255.8 any&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_30 extended permit ip 192.168.0.0 255.255.255.15 any&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_30 extended permit ip 192.168.0.0 255.255.3.0 any&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_30 extended permit ip 192.168.0.0 255.255.5.5 any&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_30 extended permit ip 192.0.0.0 255.8.4.6 any&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_30 extended permit ip 192.168.0.0 255.255.9.4 any&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_30 extended permit ip 192.0.0.0 255.45.9.4 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;:S&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally while configuring absolute bs I received some errors&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw2(config)# access-list outside_cryptomap_30 permit ip 192.168$&lt;/P&gt;&lt;P&gt;ERROR: IP address,mask &amp;lt;192.168.0.0,255.5.5.5&amp;gt; doesn't pair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw2/vander-made.nl(config)# access-list outside_cryptomap_30 extended permit i$&lt;/P&gt;&lt;P&gt;ERROR: IP address,mask &amp;lt;192.168.0.0,255.2.9.4&amp;gt; doesn't pair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any idea why you configure these kind of subnetmasks? I mean it's nowhere near a valid subnetmask/wildcardmask right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of cours on interface config it won't accept anything of the above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried it in both 8.2.x and 8.4.x software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking forward to a reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards.&lt;/P&gt;&lt;P&gt;Niels.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-accepts-non-existing-subnetmask-in-acl/m-p/1981795#M440798</guid>
      <dc:creator>Niels van der Made</dc:creator>
      <dc:date>2019-03-11T23:19:48Z</dc:date>
    </item>
    <item>
      <title>ASA accepts non existing subnetmask in ACL</title>
      <link>https://community.cisco.com/t5/network-security/asa-accepts-non-existing-subnetmask-in-acl/m-p/1981796#M440799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, those are incorrect mask, and ASA does not check whether the subnet mask has been correctly configured or not. It is simply just a user misconfiguration if incorrect mask has been entered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2012 13:29:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-accepts-non-existing-subnetmask-in-acl/m-p/1981796#M440799</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-15T13:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA accepts non existing subnetmask in ACL</title>
      <link>https://community.cisco.com/t5/network-security/asa-accepts-non-existing-subnetmask-in-acl/m-p/1981797#M440800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the subnet-masks you are talking about are no subnet-masks. They are just masks. Sounds strange?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here an example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have 200 Branch-Offices 10.10.x.0/24&lt;/P&gt;&lt;P&gt;You know that in these branches, the local FTP-server has always the IP .21.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To allow the access to all these servers you could add 200 ACEs to your ACL (with or without object-groups):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list INSIDE-IN permit tcp .... host 10.10.1.21 eq 21&lt;/P&gt;&lt;P&gt;access-list INSIDE-IN permit tcp .... host 10.10.2.21 eq 21&lt;/P&gt;&lt;P&gt;access-list INSIDE-IN permit tcp .... host 10.10.3.21 eq 21&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;access-list INSIDE-IN permit tcp .... host 10.10.200.21 eq 21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead of this you could use the following one line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list INSIDE-IN permit tcp .... 10.10.0.21 255.255.0.255 eq 21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this "strange" mask you tell your ASA that the first, second and forth Octet should be matched, but in the third octed any number is allowed (0-255).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So there is a usecase for this masks. Personally I would not recommend using them as the ASDM can not display them correctly. But they still work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, Karsten&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2012 00:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-accepts-non-existing-subnetmask-in-acl/m-p/1981797#M440800</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-06-19T00:26:01Z</dc:date>
    </item>
  </channel>
</rss>

