<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA access list query in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-access-list-query/m-p/1348225#M777289</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;Apologies, my mistake.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;It is infact &lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;192.168.100.0 255.255.255.252&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;With these networks of hosts involved, i believe the acls wont work as required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;Please suggest.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Dec 2009 16:17:49 GMT</pubDate>
    <dc:creator>suthomas1</dc:creator>
    <dc:date>2009-12-07T16:17:49Z</dc:date>
    <item>
      <title>ASA access list query</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-list-query/m-p/1348223#M777287</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have certain rules in firewall as below:&lt;BR /&gt;&lt;BR /&gt;acl servers_in line 1 extended permit tcp 192.168.100.2 255.255.255.252 host 10.83.0.2 eq 443&lt;BR /&gt;acl servers_in line 2 extended permit tcp 192.168.100.2 255.255.255.252 host 10.83.0.2 eq 445&lt;BR /&gt;acl servers_in line 3 deny ip 192.168.100.2 255.255.255.252 any&lt;BR /&gt;&lt;BR /&gt;acl servers_in line 4 extended permit tcp 192.168.100.10 255.255.255.224 host 10.83.0.10 eq 25&lt;BR /&gt;acl servers_in line 5 extended permit tcp 192.168.100.10 255.255.255.224 host 10.83.0.11 eq 80&lt;BR /&gt;acl servers_in line 6 deny ip 192.168.100.10 255.255.255.224 any &lt;BR /&gt;&lt;BR /&gt;acl servers_in line 7 permit ip 192.168.100.0 255.255.255.0 any&lt;BR /&gt;&lt;BR /&gt;My goal is to restrict 192.168.100.2 /30 to only 10.83.0.2 on specific service. similar goes for the other from line 4-6.&lt;BR /&gt;&amp;amp; deny these 192.168.100.2 /30 &amp;amp; 192.168.100.10 255.255.255.224 from accessing anything else, which is why i &lt;BR /&gt;thought of putting deny after these.&lt;BR /&gt;however due to some other reasons, i cant do away with line 7.&lt;BR /&gt;With this i find restrictive lines 1-2 and 3-4 arent really working. whereas if i remove the deny it works properly(as it should).&lt;BR /&gt;Please help me to align &amp;amp; have proper rules in place so that i can stil restrict the groups to what they are required to.&lt;BR /&gt;&lt;BR /&gt;Thank You.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-list-query/m-p/1348223#M777287</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-11T16:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA access list query</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-list-query/m-p/1348224#M777288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorta surprised that the firewall let you put in an ACL with a non-pairing IP/mask (&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;192.168.100.2 255.255.255.252). When you specify the subnet mask the IP must be the network IP not a 'host' IP, unless the mask is /32. You might try the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;acl servers_in line 1 extended permit tcp host 192.168.100.2 host 10.83.0.2 eq 443&lt;BR /&gt;acl servers_in line 2 extended permit tcp host 192.168.100.2 host 10.83.0.2 eq 445&lt;BR /&gt;acl servers_in line 3 extended deny ip host 192.168.100.2 any&lt;BR /&gt;&lt;BR /&gt;acl servers_in line 4 extended permit tcp &lt;/SPAN&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;host &lt;/SPAN&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;192.168.100.10 host 10.83.0.10 eq 25&lt;BR /&gt;acl servers_in line 5 extended permit tcp &lt;/SPAN&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;host &lt;/SPAN&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;192.168.100.10 host 10.83.0.11 eq 80&lt;BR /&gt;acl servers_in line 6 extended deny ip &lt;/SPAN&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;host &lt;/SPAN&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;192.168.100.10 any &lt;BR /&gt;&lt;BR /&gt;acl servers_in line 7 extended permit ip 192.168.100.0 255.255.255.0 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Dec 2009 15:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-list-query/m-p/1348224#M777288</guid>
      <dc:creator>busterswt</dc:creator>
      <dc:date>2009-12-07T15:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA access list query</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-list-query/m-p/1348225#M777289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;Apologies, my mistake.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;It is infact &lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;192.168.100.0 255.255.255.252&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;With these networks of hosts involved, i believe the acls wont work as required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,sans-serif;"&gt;Please suggest.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Dec 2009 16:17:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-list-query/m-p/1348225#M777289</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2009-12-07T16:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA access list query</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-list-query/m-p/1348226#M777290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;acl servers_in line 1 extended permit tcp 192.168.100.0 255.255.255.252 host 10.83.0.2 eq 443&lt;BR /&gt;acl servers_in line 2 extended permit tcp 192.168.100.0 255.255.255.252 host 10.83.0.2 eq 445&lt;BR /&gt;acl servers_in line 3 deny ip 192.168.100.2 255.255.255.252 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acl servers_in line 4 extended permit 192.168.100.0 255.255.255.224 host 10.83.0.10 eq 25&lt;BR /&gt;acl servers_in line 5 extended permit 192.168.100.0 255.255.255.224 host 10.83.0.11 eq 80&lt;BR /&gt;acl servers_in line 6 deny ip 192.168.100.10 255.255.255.224 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will ONLY allow 192.168.100.1 and .2 going to 10.83.0.2 on ports 443 and 445.&lt;BR /&gt;And ONLY 192.168.100.1 up to .30 going to 10.83.0.10 and .11 on ports 25 and 80 respectively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are those only what you want to allow?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Dec 2009 19:31:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-list-query/m-p/1348226#M777290</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-12-08T19:31:06Z</dc:date>
    </item>
  </channel>
</rss>

