<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl/m-p/1245599#M818270</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx for ur help buddy......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Sep 2009 09:40:52 GMT</pubDate>
    <dc:creator>gandhi.ganesh</dc:creator>
    <dc:date>2009-09-10T09:40:52Z</dc:date>
    <item>
      <title>ACL</title>
      <link>https://community.cisco.com/t5/network-security/acl/m-p/1245595#M818156</link>
      <description>&lt;P&gt;Three questions:&lt;/P&gt;&lt;P&gt;1. I need to allow internet for inside users say(ports 80,443)which interface i need to apply the acl &amp;amp; has what?&lt;/P&gt;&lt;P&gt;2. I need to access the FTP server in internet from one particular system in inside say(system ip 192.168.100.25 &amp;amp; ftp 216.87.172.x)what will be the acl &amp;amp; which interface we need to apply.&lt;/P&gt;&lt;P&gt;3. let say i have natted one inside system with public IP i have to access this system thru rdp(port 3389) from internet. what is the acl &amp;amp; where we need to apply?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl/m-p/1245595#M818156</guid>
      <dc:creator>gandhi.ganesh</dc:creator>
      <dc:date>2019-03-11T16:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: ACL</title>
      <link>https://community.cisco.com/t5/network-security/acl/m-p/1245596#M818199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gandhi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer your questions:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) No acl is requried - all traffic is allowed from the inside to the outside by default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) See 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Your acl would read something like:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside-in permit tcp any host &amp;lt;&lt;STATIC outside="" ip=""&gt;&amp;gt; eq 3389&lt;/STATIC&gt;&lt;/P&gt;&lt;P&gt;access-group outside-in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Sep 2009 08:26:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl/m-p/1245596#M818199</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-09-10T08:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACL</title>
      <link>https://community.cisco.com/t5/network-security/acl/m-p/1245597#M818231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;my second question was :&lt;/P&gt;&lt;P&gt;As a security policy we will not allow ftp access to any users to outside only &lt;/P&gt;&lt;P&gt;ondemand we will provide the access.&lt;/P&gt;&lt;P&gt;ex: inside subnet(192.168.100.0/24) &lt;/P&gt;&lt;P&gt;user who needs the access(192.168.100.50)&lt;/P&gt;&lt;P&gt;third party FTP server(216.87.X.X)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how is the ACL should look?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Sep 2009 09:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl/m-p/1245597#M818231</guid>
      <dc:creator>gandhi.ganesh</dc:creator>
      <dc:date>2009-09-10T09:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACL</title>
      <link>https://community.cisco.com/t5/network-security/acl/m-p/1245598#M818254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;based on your original post, and the last posting my acl would look something like:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside-out permit tcp 192.168.100.0 255.255.255.0 any eq 80 - inside out HTTP&lt;/P&gt;&lt;P&gt;access-list inside-out permit tcp 192.168.100.0 255.255.255.0 any eq 443 - inside out HTTPS&lt;/P&gt;&lt;P&gt;access-list inside-out permit tcp host 192.168.100.25 host 216.82.172.x eq 21 - specific inside host to external FTP server&lt;/P&gt;&lt;P&gt;access-list inside-out permit udp any any eq 53 - inside DNS&lt;/P&gt;&lt;P&gt;access-list inside-out permit icmp any any - for troubleshooting IP connectivity&lt;/P&gt;&lt;P&gt;access-list inside-out deny ip any any log - log all deny access from inside out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inside-out in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would re-write my original outside acl to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside-in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list outside-in extended permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list outside-inextended permit icmp any any traceroute&lt;/P&gt;&lt;P&gt;access-list outside-in extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-list outside-in permit tcp any host &amp;lt;&lt;STATIC outside="" ip=""&gt;&amp;gt; eq 3389&lt;/STATIC&gt;&lt;/P&gt;&lt;P&gt;access-group outside-in in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Sep 2009 09:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl/m-p/1245598#M818254</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-09-10T09:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: ACL</title>
      <link>https://community.cisco.com/t5/network-security/acl/m-p/1245599#M818270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx for ur help buddy......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Sep 2009 09:40:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl/m-p/1245599#M818270</guid>
      <dc:creator>gandhi.ganesh</dc:creator>
      <dc:date>2009-09-10T09:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACL</title>
      <link>https://community.cisco.com/t5/network-security/acl/m-p/1245600#M818279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sure - np glad to help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Sep 2009 09:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl/m-p/1245600#M818279</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-09-10T09:58:25Z</dc:date>
    </item>
  </channel>
</rss>

