<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Solution (ASA 5505) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072520#M895789</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from my understanding to ur requirements&lt;/P&gt;&lt;P&gt;u need first to disable any routing between any vlan if u have this before the traffic reach the firewall&lt;/P&gt;&lt;P&gt;like if u have a router or L3 switch dose the intervaln routing between vlans u need to disable this i mean between the noc and inside &lt;/P&gt;&lt;P&gt;put each vlan of thos in diffrent interface or subinterface in ASA&lt;/P&gt;&lt;P&gt;now in ur VPN setup u need to re design the interresting traffic ACL which is the ACL that you refer to in ur crypto map in STS&lt;/P&gt;&lt;P&gt;make permit of rource of noc vlan to remote site network any ip traffic&lt;/P&gt;&lt;P&gt;and make permit for traffic srourced fron inside to remote site that is port 80/443&lt;/P&gt;&lt;P&gt;now this traffic only will breing up the vpn tunnel&lt;/P&gt;&lt;P&gt;for more security u can make ACLs on the outside interfce as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for internet users to be authenticated in thier outbound internet access u can use CUT-through proxy have a look at the following link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if helpful Rate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 28 Sep 2008 12:34:16 GMT</pubDate>
    <dc:creator>Marwan ALshawi</dc:creator>
    <dc:date>2008-09-28T12:34:16Z</dc:date>
    <item>
      <title>Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072519#M895786</link>
      <description>&lt;P&gt;Hi, We have mutiple ASA 5505 which are installed on mutiple sites and all are connected via STS Tunnel. To enhancement the security, I have few below queries and need to have your reviews:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) In current scenario all default zone (Inside and DMZ) are in a same V-lan and we have allowed IP protocol among STS Tunnels which means we can access any remote IP from any machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I am going to make a different V-lan for our Depart (NOC) and want only from this V-lan all machine to be accessible and from Inside Zone only 80 and 443 port to be allowed for remote networks. Network scenario will be like that :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) V-lan 100 (NOC) -- Access Everything&lt;/P&gt;&lt;P&gt;2) Inside V-lan --- Aceess 443,80 port for remote sites which are connected via STS.&lt;/P&gt;&lt;P&gt;3) NOC have full access of Internet but Inside Zone users have access of only ICQ and Skype and all other web traffic to be blocked (Note : The Remote machines (Tunnel Sites) shd be opened of port 80,443 from Inside Zone). Kindly suggest one more thing if i need to allow any inside machine to allow internet then what kinf of settings is required for this. (I wud allow the internet via IP and Authendication)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!! Please Advice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please Advice.   &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:50:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072519#M895786</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2019-03-11T13:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072520#M895789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from my understanding to ur requirements&lt;/P&gt;&lt;P&gt;u need first to disable any routing between any vlan if u have this before the traffic reach the firewall&lt;/P&gt;&lt;P&gt;like if u have a router or L3 switch dose the intervaln routing between vlans u need to disable this i mean between the noc and inside &lt;/P&gt;&lt;P&gt;put each vlan of thos in diffrent interface or subinterface in ASA&lt;/P&gt;&lt;P&gt;now in ur VPN setup u need to re design the interresting traffic ACL which is the ACL that you refer to in ur crypto map in STS&lt;/P&gt;&lt;P&gt;make permit of rource of noc vlan to remote site network any ip traffic&lt;/P&gt;&lt;P&gt;and make permit for traffic srourced fron inside to remote site that is port 80/443&lt;/P&gt;&lt;P&gt;now this traffic only will breing up the vpn tunnel&lt;/P&gt;&lt;P&gt;for more security u can make ACLs on the outside interfce as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for internet users to be authenticated in thier outbound internet access u can use CUT-through proxy have a look at the following link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if helpful Rate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Sep 2008 12:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072520#M895789</guid>
      <dc:creator>Marwan ALshawi</dc:creator>
      <dc:date>2008-09-28T12:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072521#M895792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, thanks for your reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First I would know which of the software is using while configuring the user settings for allowing or denying the internate usage in the above link and do I need to have any license to use that software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I would like to know another thing, I want to give access of Skype and ICQ messanger to all entire users except internet browsing. And is it possible that I could permit few IP to access the internet by making any access-list or MPF. Please Advice as rest of the settings I can do. Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Sep 2008 12:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072521#M895792</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-09-28T12:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072522#M895796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please advice!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2008 07:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072522#M895796</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-09-29T07:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072523#M895801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok&lt;/P&gt;&lt;P&gt;in the above link the authentication were thorugh external database on cisco ACS whihc should be bought from cisco but if u have small number of usernames u can use local dtata base on the ASA instead of puting the AAA group use the local command&lt;/P&gt;&lt;P&gt;and creat manule username and password&lt;/P&gt;&lt;P&gt;like&lt;/P&gt;&lt;P&gt;username [usrname] password [password]&lt;/P&gt;&lt;P&gt;and this why u can use the cut-through authentication against local usernames&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;even in this case u cam make the internat access based on user names instead of IP with ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;u can permit internet access for spisific users based in thier IPs by useing ACL on the inside interface in the inbound direction awwlon http,https for those IPs and deny others&lt;/P&gt;&lt;P&gt;for messenger it is quite complicated if u wanna only deny the messenge use it is easy by using MPF &lt;/P&gt;&lt;P&gt;what i suggest u is have a look at the following link it is to block messenger but try to revers it &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808c38a6.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808c38a6.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck &lt;/P&gt;&lt;P&gt;if helpful Rate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2008 07:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072523#M895801</guid>
      <dc:creator>Marwan ALshawi</dc:creator>
      <dc:date>2008-09-29T07:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072524#M895808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agreed, but we have high number of users so wht do you suggest shd i go with Proxy.. if yes can you recommanded any free proxy server if you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second, I want to allow ICQ and SKYPE messanger for all users. My meant that by default all users ICQ and SKYPE traffic must be allowed by the FW without any blocking and rest of the things must be blocked like www, https or etc and for givivg the access of rest of the things I want to allow only few users by doing few settings on FW as u adviced or can go with Proxy. Please advice!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2008 08:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072524#M895808</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-09-29T08:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072525#M895813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please advice??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2008 12:37:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072525#M895813</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-09-29T12:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072526#M895816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 permit tcp/udp source any eq [tcp/udp messenger port number]&lt;/P&gt;&lt;P&gt;access-lsit 100 permit tcp source [IPs for who u want them to use internet] any eq http/https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if helpful Rate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 05:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072526#M895816</guid>
      <dc:creator>Marwan ALshawi</dc:creator>
      <dc:date>2008-09-30T05:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072527#M895818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks!!! Is it possible through MFP. Please suggest...which one option is better to implement.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 06:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072527#M895818</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-09-30T06:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072528#M895821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ray the thing is &lt;/P&gt;&lt;P&gt;with ACL u r working on L3/L4 while with MPF u work on L7 and with application layer u can have more flixibilty &lt;/P&gt;&lt;P&gt;for example in ACL u can permit or deny http traffic while with mpf u can only deny any undesired content in the http header&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i would say try both ways and see which one will help u more&lt;/P&gt;&lt;P&gt;maybe u need both each one to do part of the job at least u have the idea now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck&lt;/P&gt;&lt;P&gt;if helpful Rate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 12:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072528#M895821</guid>
      <dc:creator>Marwan ALshawi</dc:creator>
      <dc:date>2008-09-30T12:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Solution (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072529#M895824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks!!! got it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 13:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solution-asa-5505/m-p/1072529#M895824</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-09-30T13:36:00Z</dc:date>
    </item>
  </channel>
</rss>

