<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic idsm-vacl-help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615403#M65646</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please clarify on the below configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use eigrp,bgp, multicast,ipx on the network. can someone please clarify the below config specially the access-list allow_all and the action. The access-list do have ip any any. Since we use eigrp,multicast, ipx we have added the extra lines we think are required. dont want the network to crash after the application of vlan access-list. will this cover all traffic we have?Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan access-map IDS_CAPTURE 10&lt;BR /&gt; match ip address customized_traffic&lt;BR /&gt; action forward capture&lt;/P&gt;&lt;P&gt;vlan access-map IDS_CAPTURE 20&lt;BR /&gt; match ip address allow_all&lt;BR /&gt; action forward &lt;BR /&gt;!&lt;BR /&gt;vlan filter IDS_CAPTURE vlan-list 29-30,40,60,90,100&lt;/P&gt;&lt;P&gt;ip access-list extended allow_all&lt;BR /&gt; permit ip any any&lt;BR /&gt; permit 111 any any (ipx)&lt;BR /&gt; permit icmp any any&lt;BR /&gt; permit eigrp any any&lt;BR /&gt; permit pim any any&lt;BR /&gt;ip access-list extended customized_traffic&lt;BR /&gt; deny&amp;nbsp;&amp;nbsp; ip 10.10.60.0 0.0.0.255 10.10.40.0 0.0.0.255&lt;BR /&gt; deny&amp;nbsp;&amp;nbsp; ip 10.10.40.0 0.0.0.255 10.10.60.0 0.0.0.255&lt;BR /&gt; permit ip 10.10.60.0 0.0.0.255 10.10.30.0 0.0.0.255&lt;BR /&gt; permit ip 10.10.30.0 0.0.0.255 10.10.60.0 0.0.0.255&lt;BR /&gt; permit ip 10.10.30.0 0.0.0.255 10.10.40.0 0.0.0.255&lt;BR /&gt; permit ip 10.10.40.0 0.0.0.255 10.10.30.0 0.0.0.255&lt;BR /&gt; permit icmp any host 10.10.60.11&lt;BR /&gt; permit icmp host 10.10.60.11 any&lt;BR /&gt; permit ip any any&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:16:08 GMT</pubDate>
    <dc:creator>networksecurity2010</dc:creator>
    <dc:date>2019-03-10T12:16:08Z</dc:date>
    <item>
      <title>idsm-vacl-help</title>
      <link>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615403#M65646</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please clarify on the below configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use eigrp,bgp, multicast,ipx on the network. can someone please clarify the below config specially the access-list allow_all and the action. The access-list do have ip any any. Since we use eigrp,multicast, ipx we have added the extra lines we think are required. dont want the network to crash after the application of vlan access-list. will this cover all traffic we have?Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan access-map IDS_CAPTURE 10&lt;BR /&gt; match ip address customized_traffic&lt;BR /&gt; action forward capture&lt;/P&gt;&lt;P&gt;vlan access-map IDS_CAPTURE 20&lt;BR /&gt; match ip address allow_all&lt;BR /&gt; action forward &lt;BR /&gt;!&lt;BR /&gt;vlan filter IDS_CAPTURE vlan-list 29-30,40,60,90,100&lt;/P&gt;&lt;P&gt;ip access-list extended allow_all&lt;BR /&gt; permit ip any any&lt;BR /&gt; permit 111 any any (ipx)&lt;BR /&gt; permit icmp any any&lt;BR /&gt; permit eigrp any any&lt;BR /&gt; permit pim any any&lt;BR /&gt;ip access-list extended customized_traffic&lt;BR /&gt; deny&amp;nbsp;&amp;nbsp; ip 10.10.60.0 0.0.0.255 10.10.40.0 0.0.0.255&lt;BR /&gt; deny&amp;nbsp;&amp;nbsp; ip 10.10.40.0 0.0.0.255 10.10.60.0 0.0.0.255&lt;BR /&gt; permit ip 10.10.60.0 0.0.0.255 10.10.30.0 0.0.0.255&lt;BR /&gt; permit ip 10.10.30.0 0.0.0.255 10.10.60.0 0.0.0.255&lt;BR /&gt; permit ip 10.10.30.0 0.0.0.255 10.10.40.0 0.0.0.255&lt;BR /&gt; permit ip 10.10.40.0 0.0.0.255 10.10.30.0 0.0.0.255&lt;BR /&gt; permit icmp any host 10.10.60.11&lt;BR /&gt; permit icmp host 10.10.60.11 any&lt;BR /&gt; permit ip any any&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615403#M65646</guid>
      <dc:creator>networksecurity2010</dc:creator>
      <dc:date>2019-03-10T12:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: idsm-vacl-help</title>
      <link>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615404#M65648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you have 'permit ip any any' in the first VACL clause, no IP traffic will ever hit the second VACL clause.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Feb 2011 07:25:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615404#M65648</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2011-02-20T07:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: idsm-vacl-help</title>
      <link>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615405#M65650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Thanks for the response&lt;/P&gt;&lt;P&gt;ip any any in the customized_traffic has clause with action capture , can you please clarify the second clause with action as forward will not be hit. shouldnt the action capture should only capture the traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my other question about the protocol number ipx (111), eigrp, igmp,pim ,we think its required though we have ip any any permit in the second clause. will can you please enhance on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Feb 2011 13:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615405#M65650</guid>
      <dc:creator>networksecurity2010</dc:creator>
      <dc:date>2011-02-21T13:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: idsm-vacl-help</title>
      <link>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615406#M65652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got your point because only forwarded packets can be captured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so in my first clause i can have with action forward and capture&lt;/P&gt;&lt;P&gt;permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in my second clause i can have only forward and no capture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit 111 (ipx) any any&lt;/P&gt;&lt;P&gt;permit eigrp any any&lt;/P&gt;&lt;P&gt;permit igmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then i can control which vlans i can add in the filter list to capture traffic&lt;/P&gt;&lt;P&gt;i have a question if you can please answer&lt;/P&gt;&lt;P&gt;MSFCA -vlan10---MSFC vlan20 ---fwsm vlan20. Valns 30,40,50 assigned to vlan fwsm. Valn 10 of msfc connected to ISP&lt;/P&gt;&lt;P&gt;then in caputre list we add vlans20,30,40,50. If a host on the interenet which gets routed via vlan 10 ( can be any ip address) say 4.2.2.16 access an ip address 40.2.2.2. This 40.2.2.2 is vlan 20&lt;/P&gt;&lt;P&gt;so the packet from 4.2.2.16 comes to vlan 10 on msfc for 40.2.2.2 , msfc looks for arp on vlan 20,fwsm has a static for 40.2.2.2 with 192.168.30.2 which is on vlan 30, the packet then goes from vlan 20 with source as 4.2.2.16 and nat to 192.168.30.2 from fwsm to vlan 30 . destination replies back , packet goes from vlan 30, 20 and 10&lt;/P&gt;&lt;P&gt;The question is packet is originated from vlan 10, goes to vlan 20 and then reach 30 and vic versa. but vlan filter and idsm is configured to capture traffic vlan 20,30. will the traffic from source 40.2.2.2 will be captured and if anything malicious will idsm fire an alert&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Feb 2011 14:27:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615406#M65652</guid>
      <dc:creator>networksecurity2010</dc:creator>
      <dc:date>2011-02-21T14:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: idsm-vacl-help</title>
      <link>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615407#M65654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i understand your packet flow correctly; the packet should reach the IDSM-2 in the described scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best way is to enable the ICMP ECHO/ECHO REPLY signatures and test out the scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if helpful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Feb 2011 08:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-vacl-help/m-p/1615407#M65654</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2011-02-22T08:37:36Z</dc:date>
    </item>
  </channel>
</rss>

