<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can a ASA 5506-X be configured to limit what IP addresses can connect to a Remote Access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814580#M6629</link>
    <description>Rahul,&lt;BR /&gt;&lt;BR /&gt;I am still new to configuring ASAs. This seems like it is a two step process:&lt;BR /&gt;&lt;BR /&gt;- create the access-list&lt;BR /&gt;- create the control-plane ACL&lt;BR /&gt;&lt;BR /&gt;I am missing a detail to get this to work.&lt;BR /&gt;</description>
    <pubDate>Tue, 05 Mar 2019 22:54:29 GMT</pubDate>
    <dc:creator>dougreid</dc:creator>
    <dc:date>2019-03-05T22:54:29Z</dc:date>
    <item>
      <title>Can a ASA 5506-X be configured to limit what IP addresses can connect to a Remote Access</title>
      <link>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814397#M6623</link>
      <description>&lt;P&gt;Need to enable some more security to a clients network. &amp;nbsp; Can a set of Iist of allowed IP addresses for VPN remote access?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814397#M6623</guid>
      <dc:creator>dougreid</dc:creator>
      <dc:date>2020-02-21T16:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can a ASA 5506-X be configured to limit what IP addresses can connect to a Remote Access</title>
      <link>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814442#M6624</link>
      <description>&lt;P&gt;You can create a new control-plane ACL and apply it to the outside interface. This ACL limits what source ip addresses can hit the ASA on port 443.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example access-group below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="pCENB_CmdEnv_NoBold"&gt;&lt;STRONG class="cCN_CmdName"&gt;access-group&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cArgument"&gt;access_list&amp;nbsp;&lt;/EM&gt;&lt;STRONG class="cKeyword"&gt;in&lt;/STRONG&gt;&lt;STRONG class="cKeyword"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;interface&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cArgument"&gt;interface_name&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;STRONG class="cKeyword"&gt;control-plane&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="pCENB_CmdEnv_NoBold"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="pCENB_CmdEnv_NoBold"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="pCENB_CmdEnv_NoBold"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 18:38:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814442#M6624</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2019-03-05T18:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Can a ASA 5506-X be configured to limit what IP addresses can connect to a Remote Access</title>
      <link>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814463#M6625</link>
      <description>&lt;P&gt;Remote Access (IKEv1) uses UDP port 500.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 19:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814463#M6625</guid>
      <dc:creator>dougreid</dc:creator>
      <dc:date>2019-03-05T19:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can a ASA 5506-X be configured to limit what IP addresses can connect to a Remote Access</title>
      <link>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814509#M6626</link>
      <description>&lt;P&gt;Sorry, assumed it was for remote access using the AnyConnect client. Same concept though. You can use control-plane ACL to allow udp500 only from certain ip addresses to the ASA's outside interface.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 20:28:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814509#M6626</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2019-03-05T20:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Can a ASA 5506-X be configured to limit what IP addresses can connect to a Remote Access</title>
      <link>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814529#M6627</link>
      <description>&lt;P&gt;- Create access_list with each IP address that can access VPN.&lt;/P&gt;&lt;P&gt;- Create &lt;STRONG&gt;a&lt;/STRONG&gt;&lt;STRONG&gt;ccess-group&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;access_list&amp;nbsp;&lt;/EM&gt;&lt;STRONG&gt;in&lt;/STRONG&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;interface&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;interface_name&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;STRONG&gt;control-plane&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 21:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814529#M6627</guid>
      <dc:creator>dougreid</dc:creator>
      <dc:date>2019-03-05T21:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can a ASA 5506-X be configured to limit what IP addresses can connect to a Remote Access</title>
      <link>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814542#M6628</link>
      <description>RA_IP_ACCESS line 1 extended permit udp host 127.0.0.1 eq isakmp interface outside eq isakmp</description>
      <pubDate>Tue, 05 Mar 2019 21:32:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814542#M6628</guid>
      <dc:creator>dougreid</dc:creator>
      <dc:date>2019-03-05T21:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can a ASA 5506-X be configured to limit what IP addresses can connect to a Remote Access</title>
      <link>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814580#M6629</link>
      <description>Rahul,&lt;BR /&gt;&lt;BR /&gt;I am still new to configuring ASAs. This seems like it is a two step process:&lt;BR /&gt;&lt;BR /&gt;- create the access-list&lt;BR /&gt;- create the control-plane ACL&lt;BR /&gt;&lt;BR /&gt;I am missing a detail to get this to work.&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Mar 2019 22:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3814580#M6629</guid>
      <dc:creator>dougreid</dc:creator>
      <dc:date>2019-03-05T22:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can a ASA 5506-X be configured to limit what IP addresses can connect to a Remote Access</title>
      <link>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3815714#M6630</link>
      <description>&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list control-plane-acl extended permit udp host 1.1.1.1 host 2.2.2.2 eq isakmp &lt;/P&gt;
&lt;P&gt;access-group control-plane-acl in interface outside &lt;STRONG&gt;control-plane&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where 1.1.1.1 is the public ip of client and 2.2.2.2 is outside ip address of the ASA.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 15:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-asa-5506-x-be-configured-to-limit-what-ip-addresses-can/m-p/3815714#M6630</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2019-03-07T15:40:42Z</dc:date>
    </item>
  </channel>
</rss>

