<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pix 515E ACLs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-acls/m-p/393670#M551636</link>
    <description>&lt;P&gt;What is the best way and recommended way to create an ACL to deny incoming traffic from certain internet hosts? (Spammers, Malwares, etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a network-group and add their IPs to that group one at a time. Deny this group from the outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any pointer is appreciated. By the way, how do you guys create/modify acl entries when there are entries in the acl already and you want to put the new line at the top or in the middle or something. Is using a telnet client with cut and paste functionality the only way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Eric&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:55:53 GMT</pubDate>
    <dc:creator>ewong0088</dc:creator>
    <dc:date>2020-02-21T07:55:53Z</dc:date>
    <item>
      <title>Pix 515E ACLs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-acls/m-p/393670#M551636</link>
      <description>&lt;P&gt;What is the best way and recommended way to create an ACL to deny incoming traffic from certain internet hosts? (Spammers, Malwares, etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a network-group and add their IPs to that group one at a time. Deny this group from the outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any pointer is appreciated. By the way, how do you guys create/modify acl entries when there are entries in the acl already and you want to put the new line at the top or in the middle or something. Is using a telnet client with cut and paste functionality the only way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Eric&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-acls/m-p/393670#M551636</guid>
      <dc:creator>ewong0088</dc:creator>
      <dc:date>2020-02-21T07:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E ACLs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-acls/m-p/393671#M551637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eric,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would go with Object-grouping method, on you question for ACL editing, I write my ACLs on notepad editor and then cut/paste back onto the firewall. This way any mistakes can be rectified before going live!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2005 12:58:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-acls/m-p/393671#M551637</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2005-02-10T12:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E ACLs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-acls/m-p/393672#M551638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AFAIK, there isn't any direct possibility how to edit entries/lines in ACLs. There are not line numbers or something similar. So if you made a mistake you have to start it all over.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to write ACL in editor(like notepad) and then passed it to firewall. I found that this is not possible(I didn't work for me; maybe I am not clever though ;o)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2005 13:31:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-acls/m-p/393672#M551638</guid>
      <dc:creator>morbfrhtc</dc:creator>
      <dc:date>2005-02-10T13:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E ACLs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-acls/m-p/393673#M551641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;morbfrhtc&lt;/P&gt;&lt;P&gt;Sorry to have to correct you but you can edit ACL's in the manner that ewong0088 has specified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ewong0088&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look at the example below which will hopefully clarify matters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh access-list inside_access_in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in line 1 permit tcp any host ukjpm001 eq tacacs (hitcnt=87378) &lt;/P&gt;&lt;P&gt;access-list inside_access_in line 2 permit udp any host ukjpm001 eq radius (hitcnt=1879) &lt;/P&gt;&lt;P&gt;access-list inside_access_in line 3 permit udp any host ukabc001 eq radius (hitcnt=1259) &lt;/P&gt;&lt;P&gt;access-list inside_access_in line 4 permit udp any host ukdef001 eq radius (hitcnt=18) &lt;/P&gt;&lt;P&gt;access-list inside_access_in line 5 permit udp any host ukdmz001 eq radius (hitcnt=122977) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list inside_access_in line 3 permit udp any host ukabc001 eq radius (hitcnt=1259)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh access-list inside_access_in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in line 1 permit tcp any host ukjpm001 eq tacacs (hitcnt=87378) &lt;/P&gt;&lt;P&gt;access-list inside_access_in line 2 permit udp any host ukjpm001 eq radius (hitcnt=1879) &lt;/P&gt;&lt;P&gt;access-list inside_access_in line 3 permit udp any host ukdef001 eq radius (hitcnt=18) &lt;/P&gt;&lt;P&gt;access-list inside_access_in line 4 permit udp any host ukdmz001 eq radius (hitcnt=122977) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should you wish, you can also apply remarks at any point in the ACL, although I would recommend placing them at the top to clearly identify the ACL's role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2005 13:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-acls/m-p/393673#M551641</guid>
      <dc:creator>stevep</dc:creator>
      <dc:date>2005-02-10T13:48:17Z</dc:date>
    </item>
  </channel>
</rss>

