<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Limiting Outbound Access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/limiting-outbound-access/m-p/1456011#M663694</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I am currently using an ASA 5505 with Security Plus License (P/N: ASA5505-SEC-BUN-K9) Appliance.&amp;nbsp; What I am trying to do is create a multiple network and be completely separated from each other and on the inside interface (or network), I want to limit the outbound traffic.&amp;nbsp; I have at least 14 inside clients where they would be completely restricted to access the internet except for a specific IP Address and specific port.&amp;nbsp; All the rest of the IP Addresses on that subnet&amp;nbsp; would only have access to the internet if they have specified a username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please see the below configuration and please give me your feedback as to what other things I can improve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; !-- 14 Clients&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.1 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.1 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.2 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.2 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.3 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.3 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.4 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.4 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.5 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.5 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.6 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.6 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.7 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.8 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.9 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.9 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.10 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.4 eq 6260&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 4.2.2.1 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp 10.12.1.0 255.255.255.240 host 4.2.2.1 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 4.2.2.2 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp 10.12.1.0 255.255.255.240 host 4.2.2.2 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 4.2.2.3 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp 10.12.1.0 255.255.255.240 host 4.2.2.3 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 8.8.4.4 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp 10.12.1.0 255.255.255.240 host 8.8.4.4 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 8.8.8.8 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp 10.12.1.0 255.255.255.240 host 8.8.8.8 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended deny ip 10.12.1.0 255.255.255.240 any &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit ip any any &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-group Firewall_Policy in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; !-- AAA Configuration&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa-server AuthInbound protocol radius&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa-server AuthInbound (inside) host 10.12.1.245 sharedsecret timeout 5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication include any inside 10.12.1.0 255.255.255.0 0 0 AuthInbound&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa-server svrgrp1 protocol radius&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; max-failed-attempts 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.1 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.1 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.2 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.2 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.3 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.3 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.4 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.4 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.5 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.5 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.7 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.8 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.6 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.6 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.9 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude tcp/6260 inside 10.12.1.0 255.255.255.0 208.xxx.152.4 255.255.255.255 AuthInbound&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 4.2.2.1 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 4.2.2.2 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 4.2.2.3 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 8.8.4.4 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 8.8.8.8 255.255.255.255 AuthInbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I hope that someone can recommend if there are other better alternative to this type of configuration?&amp;nbsp; Also, care there anything I have to add in order to maintain a more secure and efficient environment?&amp;nbsp; Please school me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Russell&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 17:55:35 GMT</pubDate>
    <dc:creator>rmanapat</dc:creator>
    <dc:date>2019-03-11T17:55:35Z</dc:date>
    <item>
      <title>Limiting Outbound Access</title>
      <link>https://community.cisco.com/t5/network-security/limiting-outbound-access/m-p/1456011#M663694</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I am currently using an ASA 5505 with Security Plus License (P/N: ASA5505-SEC-BUN-K9) Appliance.&amp;nbsp; What I am trying to do is create a multiple network and be completely separated from each other and on the inside interface (or network), I want to limit the outbound traffic.&amp;nbsp; I have at least 14 inside clients where they would be completely restricted to access the internet except for a specific IP Address and specific port.&amp;nbsp; All the rest of the IP Addresses on that subnet&amp;nbsp; would only have access to the internet if they have specified a username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please see the below configuration and please give me your feedback as to what other things I can improve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; !-- 14 Clients&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.1 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.1 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.2 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.2 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.3 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.3 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.4 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.4 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.5 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.5 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.6 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.6 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.7 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.8 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.9 eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.9 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.10 eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 208.xxx.152.4 eq 6260&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 4.2.2.1 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp 10.12.1.0 255.255.255.240 host 4.2.2.1 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 4.2.2.2 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp 10.12.1.0 255.255.255.240 host 4.2.2.2 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 4.2.2.3 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp 10.12.1.0 255.255.255.240 host 4.2.2.3 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 8.8.4.4 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp 10.12.1.0 255.255.255.240 host 8.8.4.4 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp 10.12.1.0 255.255.255.240 host 8.8.8.8 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp 10.12.1.0 255.255.255.240 host 8.8.8.8 eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended deny ip 10.12.1.0 255.255.255.240 any &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit ip any any &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-group Firewall_Policy in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; !-- AAA Configuration&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa-server AuthInbound protocol radius&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa-server AuthInbound (inside) host 10.12.1.245 sharedsecret timeout 5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication include any inside 10.12.1.0 255.255.255.0 0 0 AuthInbound&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa-server svrgrp1 protocol radius&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; max-failed-attempts 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.1 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.1 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.2 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.2 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.3 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.3 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.4 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.4 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.5 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.5 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.7 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.8 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.6 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.6 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.9 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude tcp/6260 inside 10.12.1.0 255.255.255.0 208.xxx.152.4 255.255.255.255 AuthInbound&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 4.2.2.1 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 4.2.2.2 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 4.2.2.3 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 8.8.4.4 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 8.8.8.8 255.255.255.255 AuthInbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I hope that someone can recommend if there are other better alternative to this type of configuration?&amp;nbsp; Also, care there anything I have to add in order to maintain a more secure and efficient environment?&amp;nbsp; Please school me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Russell&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:55:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/limiting-outbound-access/m-p/1456011#M663694</guid>
      <dc:creator>rmanapat</dc:creator>
      <dc:date>2019-03-11T17:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Outbound Access</title>
      <link>https://community.cisco.com/t5/network-security/limiting-outbound-access/m-p/1456012#M663695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Russell,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firstly - there is a nice function called "Objects" see the below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800d641d.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800d641d.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest that you create a group for src/dst IP addresses, and TCP/UDP ports - this will reduce your acl.&lt;/P&gt;&lt;P&gt;Once you are happy with that - we will address future proofing the config/requirements!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jun 2010 18:31:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/limiting-outbound-access/m-p/1456012#M663695</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2010-06-07T18:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Outbound Access</title>
      <link>https://community.cisco.com/t5/network-security/limiting-outbound-access/m-p/1456013#M663697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the delay.&amp;nbsp; I have modified my access-list to use object-group.&amp;nbsp; Please see the modified configuration and anybody who can recommend maybe a more efficient and secure environment than my current configuration, I'll appreciate it.&amp;nbsp; By the way, just so you know, I don't have any DMZ or any port being allowed from the outside interface to inside.&amp;nbsp; Here's the configuration I currently have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group network Lanes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object 10.12.1.0 255.255.255.240&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group network CPAddress&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 208.xxx.152.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 208.xxx.152.2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 208.xxx.152.3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 208.xxx.152.4&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 208.xxx.152.5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 208.xxx.152.6&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 208.xxx.152.7&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 208.xxx.152.8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 208.xxx.152.9&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 208.xxx.152.10&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object 203.xxx.152.1 255.255.255.224&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group network DNS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; description: DNS Servers Address&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 4.2.2.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 4.2.2.2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 4.2.2.3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 8.8.4.4&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object host 8.8.8.8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group service CPPorts tcp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port-object eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port-object eq https&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port-object eq 6260&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group service DNSPorts tcp-udp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; description: DNS Servers TCP-UPD Ports&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port-object eq domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp object-group Lanes object-group CPAddress object-group CPPorts &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit tcp object-group Lanes object-group DNS object-group DNSPorts &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit udp object-group Lanes object-group DNS object-group DNSPorts &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended deny ip object-group Lanes any &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list Firewall_Policy extended permit ip any any &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-group Firewall_Policy in interface inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa-server AuthInbound protocol radius&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa-server AuthInbound (inside) host 10.12.1.245 sharedsecret timeout 5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication include any inside 10.12.1.0 255.255.255.0 0 0 AuthInbound&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa-server svrgrp1 protocol radius&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; max-failed-attempts 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.1 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.1 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.2 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.2 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.3 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.3 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.4 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.4 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.5 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.5 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.7 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.8 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 208.xxx.152.6 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.6 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 208.xxx.152.9 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude tcp/6260 inside 10.12.1.0 255.255.255.0 208.xxx.152.4 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude http inside 10.12.1.0 255.255.255.0 203.xxx.152.1 255.255.255.224 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude https inside 10.12.1.0 255.255.255.0 203.xxx.152.1 255.255.255.224 AuthInbound&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 4.2.2.1 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 4.2.2.2 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 4.2.2.3 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 8.8.4.4 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authentication exclude 53 inside 10.12.1.0 255.255.255.0 8.8.8.8 255.255.255.255 AuthInbound&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Thank you again in advance and please school me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Russell&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jun 2010 17:17:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/limiting-outbound-access/m-p/1456013#M663697</guid>
      <dc:creator>rmanapat</dc:creator>
      <dc:date>2010-06-17T17:17:20Z</dc:date>
    </item>
  </channel>
</rss>

