<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Extended access-list error using FQDN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741274#M493973</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@&lt;A _jive_internal="true" href="https://community.cisco.com/people/zulqurnain" id="jive-4571604623361078697801" onmouseout="" onmouseover=""&gt;zulqurnain&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Thanks for your reply. Indeed the asa does not allow me to use a hostname. The question is, how can I still make this work without going for 'any' or adding all the possible ip's it might translate too. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Nov 2011 12:31:27 GMT</pubDate>
    <dc:creator>michellp</dc:creator>
    <dc:date>2011-11-07T12:31:27Z</dc:date>
    <item>
      <title>Extended access-list error using FQDN</title>
      <link>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741271#M493970</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to add an access-list rule to allow internal servers to connect an outside host on a asa 5540. The hostname translates to multiple ip's. Normally I just lookup the ip address or one of the ip's the hostname translates too and use that in the access-list as the host. &lt;/P&gt;&lt;P&gt;For some reason the actual ip's, which are a few, are not always available so using a specific ip sometimes does not work, thus the reason I have to use the hostname instead of the ip. I have 2 hostnames. &lt;A href="http://www.hostname.com" target="_blank"&gt;www.hostname.com&lt;/A&gt; and subdomain.hostname.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is how I normally add these rules (the ip addresses are fictive):&lt;/P&gt;&lt;P&gt;access-list internet_access extended permit tcp host 192.168.50.5 host 84.115.57.121 eq www log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to add this using the hostname on our asa I get an error:&lt;/P&gt;&lt;P&gt;access-list internet_access extended permit tcp host 192.168.50.5 host &lt;A href="http://www.hostname.com/" target="_blank"&gt;www.hostname.com&lt;/A&gt;&amp;nbsp; ?&lt;BR /&gt;ERROR: % Unrecognized command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried it without the 'www', so hostname.com but same error. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I solve this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your time and help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741271#M493970</guid>
      <dc:creator>michellp</dc:creator>
      <dc:date>2019-03-11T21:46:52Z</dc:date>
    </item>
    <item>
      <title>Extended access-list error using FQDN</title>
      <link>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741272#M493971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; By the way, creating an object-group or network-object, gives the same result, error. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 08:18:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741272#M493971</guid>
      <dc:creator>michellp</dc:creator>
      <dc:date>2011-11-07T08:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Extended access-list error using FQDN</title>
      <link>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741273#M493972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far I can remember and experienced Cisco ASA does not allow you to configure access-list using hostname , access-list can only have ip-address and ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 10:48:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741273#M493972</guid>
      <dc:creator>zulqurnain</dc:creator>
      <dc:date>2011-11-07T10:48:23Z</dc:date>
    </item>
    <item>
      <title>Extended access-list error using FQDN</title>
      <link>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741274#M493973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@&lt;A _jive_internal="true" href="https://community.cisco.com/people/zulqurnain" id="jive-4571604623361078697801" onmouseout="" onmouseover=""&gt;zulqurnain&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Thanks for your reply. Indeed the asa does not allow me to use a hostname. The question is, how can I still make this work without going for 'any' or adding all the possible ip's it might translate too. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 12:31:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741274#M493973</guid>
      <dc:creator>michellp</dc:creator>
      <dc:date>2011-11-07T12:31:27Z</dc:date>
    </item>
    <item>
      <title>Extended access-list error using FQDN</title>
      <link>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741275#M493974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/people/zulqurnain" id="jive-457160965476906290454" onmouseout="" onmouseover=""&gt;zulqurnain&lt;/A&gt; is correct, you cannot add a hostname to an ACL it has to be an IP address. The only way to filter traffic is by adding the IP address and ports of&amp;nbsp; hostename.com to the ACL. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 20:45:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/extended-access-list-error-using-fqdn/m-p/1741275#M493974</guid>
      <dc:creator>chris baranowski</dc:creator>
      <dc:date>2011-11-07T20:45:37Z</dc:date>
    </item>
  </channel>
</rss>

