<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Outbound ACL's in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/outbound-acl-s/m-p/1583786#M594605</link>
    <description>&lt;P&gt;I have been fighting the ackantta virus for quite some time now. The decision has been made to lock down every port except for a select few (e.g. 80, 443, 21, 8080...)&lt;/P&gt;&lt;P&gt;My question is, "How do I create an outbound ACL that blocks all outbound traffic except for specific ports. I alerady placed a block on the ports associated with ackantta. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BrandtASA# sh run | incl access-list out&lt;BR /&gt;access-list outside extended permit tcp any host 10.1.5.50 eq smtp&lt;BR /&gt;access-list outside extended permit tcp any host 10.1.5.80 eq smtp&lt;BR /&gt;access-list outside extended permit udp any any eq domain&lt;BR /&gt;access-list outside extended permit tcp any any eq www&lt;BR /&gt;access-list outside extended permit tcp any any eq https&lt;BR /&gt;access-list outside extended permit ip 10.0.50.0 255.255.255.0 any&lt;BR /&gt;access-list outside extended permit icmp any any&lt;BR /&gt;access-list outside extended permit ip any any&lt;BR /&gt;access-list outside extended permit tcp any any eq pptp&lt;BR /&gt;access-list outside extended permit tcp any host 10.1.5.90 eq smtp&lt;BR /&gt;access-list outside extended permit tcp any host 10.1.5.91 eq smtp&lt;BR /&gt;access-list outside extended deny tcp any any eq smtp&lt;BR /&gt;access-list outside extended deny tcp any any eq whois&lt;BR /&gt;access-list outside extended deny udp any any eq 43&lt;BR /&gt;access-list outside extended deny tcp any any eq 1033&lt;BR /&gt;access-list outside extended deny udp any any eq 1033&lt;BR /&gt;access-list outside extended deny tcp any any eq 1035&lt;BR /&gt;access-list outside extended deny udp any any eq 1035&lt;BR /&gt;access-list outside extended deny tcp any any eq 1050&lt;BR /&gt;access-list outside extended deny udp any any eq 1050&lt;BR /&gt;access-list outside extended deny tcp any any eq 1052&lt;BR /&gt;access-list outside extended deny udp any any eq 1052&lt;BR /&gt;access-list outside extended deny tcp any any eq 1059&lt;BR /&gt;access-list outside extended deny udp any any eq 1059&lt;BR /&gt;access-list outside extended deny tcp any any eq 1060&lt;BR /&gt;access-list outside extended deny udp any any eq 1060&lt;BR /&gt;access-list outside extended deny tcp any any eq 1061&lt;BR /&gt;access-list outside extended deny udp any any eq 1061&lt;BR /&gt;access-list outside extended deny tcp any any eq 1062&lt;BR /&gt;access-list outside extended deny udp any any eq 1062&lt;BR /&gt;access-list outside extended deny tcp any any eq 1063&lt;BR /&gt;access-list outside extended deny udp any any eq 1063&lt;BR /&gt;access-list outside extended deny tcp any any eq 1070&lt;BR /&gt;access-list outside extended deny udp any any eq 1070&lt;BR /&gt;access-list outside extended deny tcp any any eq 1074&lt;BR /&gt;access-list outside extended deny udp any any eq 1074&lt;BR /&gt;access-list outside extended deny tcp any any eq 1087&lt;BR /&gt;access-list outside extended deny udp any any eq 1087&lt;BR /&gt;access-list outside extended deny tcp any any eq 1089&lt;BR /&gt;access-list outside extended deny udp any any eq 1089&lt;BR /&gt;access-list outside extended deny tcp any any eq 1090&lt;BR /&gt;access-list outside extended deny udp any any eq 1090&lt;BR /&gt;access-list outside extended deny tcp any any eq 1091&lt;BR /&gt;access-list outside extended deny udp any any eq 1091&lt;/P&gt;&lt;P&gt;I guess my very basic quesiton is....do I create permit statements just for the select few and deny all others?&amp;nbsp; I confused myself and have fallen and can't get up.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:33:14 GMT</pubDate>
    <dc:creator>Scott Payne</dc:creator>
    <dc:date>2019-03-11T19:33:14Z</dc:date>
    <item>
      <title>Outbound ACL's</title>
      <link>https://community.cisco.com/t5/network-security/outbound-acl-s/m-p/1583786#M594605</link>
      <description>&lt;P&gt;I have been fighting the ackantta virus for quite some time now. The decision has been made to lock down every port except for a select few (e.g. 80, 443, 21, 8080...)&lt;/P&gt;&lt;P&gt;My question is, "How do I create an outbound ACL that blocks all outbound traffic except for specific ports. I alerady placed a block on the ports associated with ackantta. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BrandtASA# sh run | incl access-list out&lt;BR /&gt;access-list outside extended permit tcp any host 10.1.5.50 eq smtp&lt;BR /&gt;access-list outside extended permit tcp any host 10.1.5.80 eq smtp&lt;BR /&gt;access-list outside extended permit udp any any eq domain&lt;BR /&gt;access-list outside extended permit tcp any any eq www&lt;BR /&gt;access-list outside extended permit tcp any any eq https&lt;BR /&gt;access-list outside extended permit ip 10.0.50.0 255.255.255.0 any&lt;BR /&gt;access-list outside extended permit icmp any any&lt;BR /&gt;access-list outside extended permit ip any any&lt;BR /&gt;access-list outside extended permit tcp any any eq pptp&lt;BR /&gt;access-list outside extended permit tcp any host 10.1.5.90 eq smtp&lt;BR /&gt;access-list outside extended permit tcp any host 10.1.5.91 eq smtp&lt;BR /&gt;access-list outside extended deny tcp any any eq smtp&lt;BR /&gt;access-list outside extended deny tcp any any eq whois&lt;BR /&gt;access-list outside extended deny udp any any eq 43&lt;BR /&gt;access-list outside extended deny tcp any any eq 1033&lt;BR /&gt;access-list outside extended deny udp any any eq 1033&lt;BR /&gt;access-list outside extended deny tcp any any eq 1035&lt;BR /&gt;access-list outside extended deny udp any any eq 1035&lt;BR /&gt;access-list outside extended deny tcp any any eq 1050&lt;BR /&gt;access-list outside extended deny udp any any eq 1050&lt;BR /&gt;access-list outside extended deny tcp any any eq 1052&lt;BR /&gt;access-list outside extended deny udp any any eq 1052&lt;BR /&gt;access-list outside extended deny tcp any any eq 1059&lt;BR /&gt;access-list outside extended deny udp any any eq 1059&lt;BR /&gt;access-list outside extended deny tcp any any eq 1060&lt;BR /&gt;access-list outside extended deny udp any any eq 1060&lt;BR /&gt;access-list outside extended deny tcp any any eq 1061&lt;BR /&gt;access-list outside extended deny udp any any eq 1061&lt;BR /&gt;access-list outside extended deny tcp any any eq 1062&lt;BR /&gt;access-list outside extended deny udp any any eq 1062&lt;BR /&gt;access-list outside extended deny tcp any any eq 1063&lt;BR /&gt;access-list outside extended deny udp any any eq 1063&lt;BR /&gt;access-list outside extended deny tcp any any eq 1070&lt;BR /&gt;access-list outside extended deny udp any any eq 1070&lt;BR /&gt;access-list outside extended deny tcp any any eq 1074&lt;BR /&gt;access-list outside extended deny udp any any eq 1074&lt;BR /&gt;access-list outside extended deny tcp any any eq 1087&lt;BR /&gt;access-list outside extended deny udp any any eq 1087&lt;BR /&gt;access-list outside extended deny tcp any any eq 1089&lt;BR /&gt;access-list outside extended deny udp any any eq 1089&lt;BR /&gt;access-list outside extended deny tcp any any eq 1090&lt;BR /&gt;access-list outside extended deny udp any any eq 1090&lt;BR /&gt;access-list outside extended deny tcp any any eq 1091&lt;BR /&gt;access-list outside extended deny udp any any eq 1091&lt;/P&gt;&lt;P&gt;I guess my very basic quesiton is....do I create permit statements just for the select few and deny all others?&amp;nbsp; I confused myself and have fallen and can't get up.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:33:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-acl-s/m-p/1583786#M594605</guid>
      <dc:creator>Scott Payne</dc:creator>
      <dc:date>2019-03-11T19:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound ACL's</title>
      <link>https://community.cisco.com/t5/network-security/outbound-acl-s/m-p/1583787#M594607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The easiest way would be to create permit lines only for the specific ports that you want to allow. All other ports will be denied by the implicit 'deny ip any any' rule at the end of every access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jan 2011 17:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-acl-s/m-p/1583787#M594607</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-01-10T17:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound ACL's</title>
      <link>https://community.cisco.com/t5/network-security/outbound-acl-s/m-p/1583788#M594609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I should just do something like the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) remove access-list outside extended permit ip any any&lt;BR /&gt;2) add permit rules to specific ports such as access-list outside extended permit tcp any any eq www&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jan 2011 17:41:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-acl-s/m-p/1583788#M594609</guid>
      <dc:creator>Scott Payne</dc:creator>
      <dc:date>2011-01-10T17:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound ACL's</title>
      <link>https://community.cisco.com/t5/network-security/outbound-acl-s/m-p/1583789#M594611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exactly. All access-lists have an implicit 'deny ip any any' line at the end even though you can't see it in the config. Because ACLs are processed sequentially and processing stops as soon as a line matches, ACL processing will never go past your 'permit ip any any' line. Instead, just put permit lines for the specific ports you do want to allow and everything else will be denied by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jan 2011 17:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-acl-s/m-p/1583789#M594611</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-01-10T17:59:55Z</dc:date>
    </item>
  </channel>
</rss>

