<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: diffence between Access rules and ACL Manager in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665504#M562560</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it's very clear and thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in my case, i want to allow outside trafic comming from Internet to my web server located in dmz, the direction of trafic will be out interface outside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet-----------ASA------------dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------&amp;gt; trafic is from internet to my asa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is my access-list and access-group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host &lt;X.X.X.X&gt; eq www&lt;/X.X.X.X&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why the access-group is in "IN" ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 14 May 2011 07:23:48 GMT</pubDate>
    <dc:creator>zain_gabon</dc:creator>
    <dc:date>2011-05-14T07:23:48Z</dc:date>
    <item>
      <title>diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665485#M562512</link>
      <description>&lt;P&gt;Dear Support,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can somebody clarify for me the difference between creating rules using Access rules and using ACL Manager?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i create a rule graphically, i see it on ASDM and when i create the same rule using cli, i cannot see it on Access rules, i can, only see it on ACL Manager, so it's not clear for between access rules and ACL Manger.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cout on you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:32:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665485#M562512</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2019-03-11T20:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665486#M562515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you create ACL's with the manager, those acls are not applied for permitting or denying traffic on an interface. They are used for matching criteria. For example, to be used no a policy nat, QoS, VPN tunnel interesting traffic etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 May 2011 23:25:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665486#M562515</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-11T23:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665487#M562520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for you quick response,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That means, if i need to create a policy for permetting trafic, i need to use Access Rules Under Firewall Menu?&lt;/P&gt;&lt;P&gt;Another Thing, when i create a policy with Access rule, it's automatically create a ACL on ACL Manager, Wht this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 06:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665487#M562520</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-05-12T06:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665488#M562521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What Mike said is absolutely correct...whenever you are creating an interface ACL you would have to do it from the ACL option, thats why you see ACL's there under each interface.&lt;/P&gt;&lt;P&gt;As per the ACL manager, those ACL's are not used for filtering incoming traffic, rather than matching the traffic in different configuration such as QoS, captures, tunnels. In the ACL manager you would see the ACL's as per their names rather than the interface.Mike was spot on for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 07:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665488#M562521</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-12T07:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665489#M562524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not really clear for me, First, i just want to allow users in inside network to access to Internet. What to do in this case?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the cli command ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 10.10.10.10 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.2.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The users are behind inside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 07:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665489#M562524</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-05-12T07:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665490#M562525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For accessing the internet from inside, you dont need an access-list, because inside interface is your highly secured network (security-level 100) and high security to low secutiy traffic is implicitly allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I woudl also suggest you to plz follow this thread, most of you questions would be answered here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-thread-small" href="https://community.cisco.com/thread/2083101"&gt;https://supportforums.cisco.com/thread/2083101?tstart=0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz let me know if you have any queries regarding it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 07:20:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665490#M562525</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-12T07:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665491#M562527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For internet access you would require the following configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;route 0 0 &lt;IP of="" next="" hop=""&gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be enough for the users to get internet access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 07:29:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665491#M562527</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-12T07:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665492#M562528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already read the think you send to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, it' not clear for me. i' have a cisco ASA 5520 on my table for making test.&lt;/P&gt;&lt;P&gt;i'm doing many scenarios and have many differences. Creating policy using CLI and ASDM and i don't have the same result, it's confused for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, i want to allow trafic from internet to go to smtp server which located on dmz (i did correctly the static nat), sometime i see a access-list under ACL, but nothing on Access Rules and vis versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 07:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665492#M562528</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-05-12T07:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665493#M562529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets take up your requirement one by one, and try and configure it through CLI(we'll leave the ASDM for a while).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your SMTP server is on the DMZ then you would need to configure the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) &lt;PUBLIC ip="" of="" server=""&gt;&amp;nbsp; &amp;lt; Real ip of server&amp;gt;&lt;/PUBLIC&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host &lt;PUBLIC ip="" of="" server=""&gt; eq 25&lt;/PUBLIC&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host &lt;PUBLIC ip="" of="" server=""&gt; eq 110&lt;/PUBLIC&gt;&lt;/P&gt;&lt;P&gt;access-group&amp;nbsp; outside_access_inin interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know what your other requirement is.&lt;/P&gt;&lt;P&gt;You might have missed this command:&lt;/P&gt;&lt;P&gt;access-group&amp;nbsp; outside_access_inin interface outside&lt;/P&gt;&lt;P&gt;this applies the ACL on outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 07:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665493#M562529</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-12T07:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665494#M562530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's work Fine,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lol Varun for your precious Help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem was to apply&amp;nbsp; the ACL on the Interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group&amp;nbsp; outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks, i understand,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 08:07:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665494#M562530</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-05-12T08:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665495#M562535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem Zain &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; , let me know if you get stuck anywhere, you can post on this thread only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 08:18:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665495#M562535</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-12T08:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665496#M562541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To close with my interrogation, please, how many access-group we can have by interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 09:55:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665496#M562541</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-05-12T09:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665497#M562545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can only have one access-group per interface, so if you have 3 interfaces then you can create just 3 access-groups, one for each interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For multiple ACL's on same interface, just keep the same names for them:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_in extended permit tcp host 192.168.2.80 host 192.168.1.12 eq smtp &lt;BR /&gt;access-list DMZ_In extended permit tcp host 192.168.2.80 host 192.168.36.7 eq smtp &lt;BR /&gt;access-list DMZ_In extended permit tcp host 192.168.2.80 host 192.168.58.12 eq smtp &lt;BR /&gt;access-list DMZ_In extended permit tcp host 192.168.2.80 host 192.168.8.21 eq smtp &lt;BR /&gt;access-list DMZ_In extended permit udp host 192.168.2.100 host 192.168.15.2 &lt;BR /&gt;access-list DMZ_In extended permit ip host 192.168.2.100 host 192.168.100.1 &lt;BR /&gt;access-list DMZ_In extended permit ip host 192.168.2.10 192.168.116.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group DMZ_In in interface DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 10:01:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665497#M562545</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-12T10:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665498#M562547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With your help, i understand my Cisco ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regars&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 10:06:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665498#M562547</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-05-12T10:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665499#M562549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have to access-group per interface.&lt;/P&gt;&lt;P&gt;1. inbound&lt;/P&gt;&lt;P&gt;2. outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E.g. access-list test extended permit ip any any&lt;BR /&gt;access-group test in interface inside&lt;BR /&gt;access-group test out interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2011 12:59:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665499#M562549</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-05-12T12:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665500#M562552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Anisha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks for your help, this really help me&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 May 2011 06:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665500#M562552</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-05-13T06:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665501#M562553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Anisha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for you help, but i want to know what is the difference between theses lines:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group test in interface inside&lt;BR /&gt;access-group test out interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when we need to use IN and when to use OUT ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 May 2011 06:30:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665501#M562553</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-05-14T06:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665502#M562556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its the difference of the direction of traffic flow out of the interface,i if the traffic is in ingress direction, then we use in interafce inside but if we want to apply&lt;/P&gt;&lt;P&gt;ACL for traffic going out of the interface we use out interface inside. Here is a sdmqall diagram:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;outside-------------------ASA--------------------Inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------------------------&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; out interafce inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;outside--------------------ASA-------------------Inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;-------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; in interafce inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this would help you in understanding it better.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 May 2011 07:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665502#M562556</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-14T07:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665503#M562559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should clear out things better:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/security/asa/asa82/command/reference/a1.html#wp1558618"&gt;http://www.cisco.com/en/US/partner/docs/security/asa/asa82/command/reference/a1.html#wp1558618&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 May 2011 07:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665503#M562559</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-14T07:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: diffence between Access rules and ACL Manager</title>
      <link>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665504#M562560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it's very clear and thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in my case, i want to allow outside trafic comming from Internet to my web server located in dmz, the direction of trafic will be out interface outside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet-----------ASA------------dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------&amp;gt; trafic is from internet to my asa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is my access-list and access-group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host &lt;X.X.X.X&gt; eq www&lt;/X.X.X.X&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why the access-group is in "IN" ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 May 2011 07:23:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/diffence-between-access-rules-and-acl-manager/m-p/1665504#M562560</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-05-14T07:23:48Z</dc:date>
    </item>
  </channel>
</rss>

