<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASDM and access rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521088#M695680</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps &lt;A href="http://www.cisco.com/en/US/docs/security/asdm/6_2/user/guide/aclrules.html#wp1046058"&gt;http://www.cisco.com/en/US/docs/security/asdm/6_2/user/guide/aclrules.html#wp1046058&lt;/A&gt;&lt;SPAN&gt; This is with ASDM version 6.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Namit &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Sep 2010 15:30:30 GMT</pubDate>
    <dc:creator>Namit Agarwal</dc:creator>
    <dc:date>2010-09-23T15:30:30Z</dc:date>
    <item>
      <title>ASDM and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521086#M695669</link>
      <description>&lt;P&gt;Can anyone give me a quick walkthrough on how to set up an access rule to block a TCP port? I need to stop people from playing a game (World of Warcraft) and I need to block 3724. I've tried various combinations of inside outgoping, inside incoming and I just can't seem to get it. I would really appreciate some help with configuring this through the ASDM GUI.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:44:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521086#M695669</guid>
      <dc:creator>Jason Sypolt</dc:creator>
      <dc:date>2019-03-11T18:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521087#M695675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the version of the ASDM and the ASA code you are running&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Namit &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 15:27:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521087#M695675</guid>
      <dc:creator>Namit Agarwal</dc:creator>
      <dc:date>2010-09-23T15:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521088#M695680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps &lt;A href="http://www.cisco.com/en/US/docs/security/asdm/6_2/user/guide/aclrules.html#wp1046058"&gt;http://www.cisco.com/en/US/docs/security/asdm/6_2/user/guide/aclrules.html#wp1046058&lt;/A&gt;&lt;SPAN&gt; This is with ASDM version 6.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Namit &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 15:30:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521088#M695680</guid>
      <dc:creator>Namit Agarwal</dc:creator>
      <dc:date>2010-09-23T15:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521089#M695687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, forgot to include that. It is ASDM 5.2(3) on an ASA 5505 7.2(3)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 15:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521089#M695687</guid>
      <dc:creator>Jason Sypolt</dc:creator>
      <dc:date>2010-09-23T15:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521090#M695696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa72/asdm52/user/guide/aclrules.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/asdm52/user/guide/aclrules.html&lt;/A&gt;&lt;SPAN&gt; hope this helps it is for ASDM 5.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Namit &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 15:50:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521090#M695696</guid>
      <dc:creator>Namit Agarwal</dc:creator>
      <dc:date>2010-09-23T15:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521091#M695707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And I'm assuming that I need to block this game on the inside network since you start the client and it connects to the external game servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I was trying to add an outgoing deny rule on the inside network for any source, any destination that has a source port of 3724.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 15:52:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521091#M695707</guid>
      <dc:creator>Jason Sypolt</dc:creator>
      <dc:date>2010-09-23T15:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521092#M695711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you blocked IP traffc or only UDP or TCP. Please block both UDP and TCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ya that should do the trick deny any connection with source port 3724 with any source IP&amp;nbsp; any destination IP . The ACL will be applied on the inside interface in the inward direction. Also make sure that this should be top of the ACL entries as there might be a permit entry allowing this traffic before it hits the deny rule. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please send the running config or at least the ACL you have applied&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;Namit &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 16:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521092#M695711</guid>
      <dc:creator>Namit Agarwal</dc:creator>
      <dc:date>2010-09-23T16:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521093#M695719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think this will be helpful, apart from what namit has said about how to block them i think you should see this, looks interesting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;The Blizzard Downloader requires that TCP ports 3724 and&amp;nbsp; 6112 be forwarded. It can also benefit from having ports 6881 through&amp;nbsp; 6999 forwarded.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i found this on some world of warcraft forum wherein people are discussing on which ports to open to allow it, and look at the 2 side of coin, you are going to look at it to block your users : )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://forums.worldofwarcraft.com/thread.html?topicId=2215453407&amp;amp;sid=1"&gt;http://forums.worldofwarcraft.com/thread.html?topicId=2215453407&amp;amp;sid=1&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 16:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521093#M695719</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-09-23T16:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521094#M695726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeetu thanks for the information. That is very useful. However the port 3724 is the one that is used for hosting the game. Rest of the ports are just used for downloading the patches by the Blizzard Support. I think just blocking 3724 should be enough. However as per documentation on Blizzard Support Site they have mentioned the following ports to be opened in order to run this. 3724, 6112, 6113, 6114 and 4000. &lt;A class="active_link" href="http://us.blizzard.com/support/article.xml?locale=en_US&amp;amp;articleId=21077"&gt;http://us.blizzard.com/support/article.xml?locale=en_US&amp;amp;articleId=21077&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think we can start by blocking 3724 and of it does not help we can move on to blocking other ports as well. Moreover Jason please send the running config or the screenshot of the ACL you are configuring using the ASDM, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Namit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 17:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521094#M695726</guid>
      <dc:creator>Namit Agarwal</dc:creator>
      <dc:date>2010-09-23T17:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM and access rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521095#M695732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the help thus far. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny udp any eq 3724 any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny tcp any object-group WoW_TCP any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... and the network object group that the ACL refers to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service WoW_TCP tcp&lt;/P&gt;&lt;P&gt; port-object range 1119 1119&lt;/P&gt;&lt;P&gt; port-object range 3724 3724&lt;/P&gt;&lt;P&gt; port-object range 4000 4000&lt;/P&gt;&lt;P&gt; port-object range 6112 6114&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Sep 2010 11:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-and-access-rules/m-p/1521095#M695732</guid>
      <dc:creator>Jason Sypolt</dc:creator>
      <dc:date>2010-09-24T11:57:03Z</dc:date>
    </item>
  </channel>
</rss>

