<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL vs. Access List Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907195#M5721</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292167"&gt;@Brendan Wood&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;What is the purpose of the access-group statement here?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;With the access-list command you create the lists in global mode.&lt;BR /&gt;With the access-group command you apply the ACL on the interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Would the ACL work on it's own or does it have to be "applied" with the access-group command above?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;ACLs are created in the global mode, but they have no effect if they are not applied to any interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Should I have a different access-group for each interface?&amp;nbsp; For example, stuff going from public to inside, from public to DMZ, etc.?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;An ACL can be applied in several interfaces, if the indications of that ACL are useful in all such cases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Tue, 13 Aug 2019 03:02:29 GMT</pubDate>
    <dc:creator>luis_cordova</dc:creator>
    <dc:date>2019-08-13T03:02:29Z</dc:date>
    <item>
      <title>ACL vs. Access List Question</title>
      <link>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907150#M5716</link>
      <description>&lt;P&gt;Hello,&amp;nbsp; I'm in the process of setting up a replacement ASA right now and I have a question about access lists.&lt;/P&gt;&lt;P&gt;I have an ACL defined like:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;access-list outside_access_in extended permit tcp any object host:srv-dmz-l-prj01 eq 1221&lt;/PRE&gt;&lt;P&gt;And I have a line like this elsewhere in my config:&lt;/P&gt;&lt;PRE&gt;access-group outside_access_in in interface outside&lt;/PRE&gt;&lt;P&gt;My questions would be:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;What is the purpose of the access-group statement here?&lt;/LI&gt;&lt;LI&gt;Would the ACL work on it's own or does it have to be "applied" with the access-group command above?&lt;/LI&gt;&lt;LI&gt;Should I have a different access-group for each interface?&amp;nbsp; For example, stuff going from public to inside, from public to DMZ, etc.?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I'm very junior with the Cisco ASA, so please dumb down your answers.&amp;nbsp; :&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:23:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907150#M5716</guid>
      <dc:creator>Brendan Wood</dc:creator>
      <dc:date>2020-02-21T17:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: ACL vs. Access List Question</title>
      <link>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907152#M5720</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Access-lists&lt;/STRONG&gt; are created globally and then applied with the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;access-group&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;command. They can be applied in&amp;nbsp; or outbound.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 00:22:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907152#M5720</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-08-13T00:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACL vs. Access List Question</title>
      <link>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907195#M5721</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292167"&gt;@Brendan Wood&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;What is the purpose of the access-group statement here?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;With the access-list command you create the lists in global mode.&lt;BR /&gt;With the access-group command you apply the ACL on the interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Would the ACL work on it's own or does it have to be "applied" with the access-group command above?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;ACLs are created in the global mode, but they have no effect if they are not applied to any interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Should I have a different access-group for each interface?&amp;nbsp; For example, stuff going from public to inside, from public to DMZ, etc.?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;An ACL can be applied in several interfaces, if the indications of that ACL are useful in all such cases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 03:02:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907195#M5721</guid>
      <dc:creator>luis_cordova</dc:creator>
      <dc:date>2019-08-13T03:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACL vs. Access List Question</title>
      <link>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907213#M5722</link>
      <description>&lt;P&gt;Very clear and understood.&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 03:24:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907213#M5722</guid>
      <dc:creator>Brendan Wood</dc:creator>
      <dc:date>2019-08-13T03:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACL vs. Access List Question</title>
      <link>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907256#M5723</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292167"&gt;@Brendan Wood&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remember to mark the correct answers as solved, because that helps other users with similar questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 05:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-vs-access-list-question/m-p/3907256#M5723</guid>
      <dc:creator>luis_cordova</dc:creator>
      <dc:date>2019-08-13T05:42:22Z</dc:date>
    </item>
  </channel>
</rss>

