<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL Commands on new ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-commands-on-new-asa/m-p/1486529#M663337</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're absolutately right.&lt;/P&gt;&lt;P&gt;You want to restrict the ACE statements as much as possible. (avoid ''any'' wherever you can).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, to make the ACL more manageable, use object groups is the recommendation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Jun 2010 15:08:29 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2010-06-11T15:08:29Z</dc:date>
    <item>
      <title>ACL Commands on new ASA</title>
      <link>https://community.cisco.com/t5/network-security/acl-commands-on-new-asa/m-p/1486528#M663324</link>
      <description>&lt;P&gt;Hello:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am replacing my PIX with a new ASA.&amp;nbsp; When my PIX was deployed I used a consultant to get it online quickly.&amp;nbsp; Later I realized he used a lot of wild cards in the config.&amp;nbsp; (any to any)&amp;nbsp; Since the initial deployment I cleaned a lot of them up.&amp;nbsp; Here is my question.&amp;nbsp; I have always used the guideline the firewall should be very secure.&amp;nbsp; No traffic should be able to pass out or in unless I allow it.&amp;nbsp; There are some "any to any" ACL's in for services like DNS and some others.&amp;nbsp; I like to use "object-groups" in my config and group my networks and hosts.&amp;nbsp; This will ultimately make the config bigger and thus create more processing power on the ASA.&amp;nbsp; Am I right to use the "object-group" for these types of services or am I just over thinking this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Harrison Midkiff&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-commands-on-new-asa/m-p/1486528#M663324</guid>
      <dc:creator>HMidkiff</dc:creator>
      <dc:date>2019-03-11T17:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: ACL Commands on new ASA</title>
      <link>https://community.cisco.com/t5/network-security/acl-commands-on-new-asa/m-p/1486529#M663337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're absolutately right.&lt;/P&gt;&lt;P&gt;You want to restrict the ACE statements as much as possible. (avoid ''any'' wherever you can).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, to make the ACL more manageable, use object groups is the recommendation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jun 2010 15:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-commands-on-new-asa/m-p/1486529#M663337</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-11T15:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACL Commands on new ASA</title>
      <link>https://community.cisco.com/t5/network-security/acl-commands-on-new-asa/m-p/1486530#M663355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Grouping like items is exactly what object groups are for.&amp;nbsp; It make the config easier to look at and adding or removing a host from a group is easier than re-writing the ACE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jun 2010 15:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-commands-on-new-asa/m-p/1486530#M663355</guid>
      <dc:creator>terrygwazdosky</dc:creator>
      <dc:date>2010-06-11T15:08:42Z</dc:date>
    </item>
  </channel>
</rss>

