<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA: Assign same rule sets to multiple interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-assign-same-rule-sets-to-multiple-interfaces/m-p/2511832#M934535</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;We want to connect to physical interfaces from ASA to each Nexus core, so is there any possibility to assign same rule set to both interfaces simultaneously? (a kind of zone aggregation).&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Jesus&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 13:12:39 GMT</pubDate>
    <dc:creator>JPavonM</dc:creator>
    <dc:date>2020-02-21T13:12:39Z</dc:date>
    <item>
      <title>Cisco ASA: Assign same rule sets to multiple interfaces</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-assign-same-rule-sets-to-multiple-interfaces/m-p/2511832#M934535</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;We want to connect to physical interfaces from ASA to each Nexus core, so is there any possibility to assign same rule set to both interfaces simultaneously? (a kind of zone aggregation).&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Jesus&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:12:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-assign-same-rule-sets-to-multiple-interfaces/m-p/2511832#M934535</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2020-02-21T13:12:39Z</dc:date>
    </item>
    <item>
      <title>Hi  What is Your ASA Code</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-assign-same-rule-sets-to-multiple-interfaces/m-p/2511833#M934537</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;What is Your ASA Code running on your ASA appliance , From ASA code 8.3 you can have global access rule .&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" bordercolor="#808080" cellpadding="3" cellspacing="0" id="wp1120636table1120630" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pComment" style="color: red; font-size: 12px; font-style: italic; margin: 1px 0em 6px; text-indent: 0em;"&gt;lobal access rules.&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1120658"&gt;&lt;/A&gt;&lt;P class="pB1_Body1" style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;8.3(1)&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1120660"&gt;&lt;/A&gt;&lt;P class="pB1_Body1" style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;Global access rules were introduced.&lt;/P&gt;&lt;A name="wp1139574"&gt;&lt;/A&gt;&lt;P class="pB1_Body1" style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;The following command was modified:&amp;nbsp;&lt;B class="cBold"&gt;access-group&lt;/B&gt;.&lt;/P&gt;&lt;A name="wp1120662"&gt;&lt;/A&gt;&lt;P class="pB1_Body1" style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;Interface access rules are bound to any interface at the time of their creation. Without binding them to an interface, you can not create them. This differs from the Command Line example. With CLI, you first create the access list with the&amp;nbsp;&lt;B&gt;access list&lt;/B&gt;command, and then bind this access list to an interface with the&amp;nbsp;&lt;B&gt;access-group&lt;/B&gt;&amp;nbsp;command. ASDM 6.3 and later, the access list is created and bound to an interface as a single task. This applies to the traffic flowing through that specific interface only.&lt;/P&gt;&lt;P style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;&lt;STRONG&gt;Global access rules are not bound to any interface. They can be configured through the ACL Manager tab in the ASDM and are applied to the global ingress traffic. They are implemented when there is a match based on the source, the destination, and the protocol type. These rules are not replicated on each interface, so they save memory space.&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;When both these rules are to be implemented, interface access rules normally takes the precedence &lt;STRONG&gt;over the global access rules.&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;&lt;STRONG&gt;HTH&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;&lt;STRONG&gt;Sandy&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 12:51:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-assign-same-rule-sets-to-multiple-interfaces/m-p/2511833#M934537</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-06-18T12:51:12Z</dc:date>
    </item>
    <item>
      <title>Hi Sandy and thank you for</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-assign-same-rule-sets-to-multiple-interfaces/m-p/2511834#M934539</link>
      <description>&lt;P&gt;Hi Sandy and thank you for the information,&lt;/P&gt;&lt;P&gt;I have in mind to apply access-group sentence over the two interfaces, inside1 and inside2, with the same access list set, but I think global access rules can be as good as is, as they only apply to source and destination without taken care of the incoming interface.&lt;/P&gt;&lt;P&gt;I will update the post with the result in short.&lt;/P&gt;&lt;P&gt;Jesus&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 13:03:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-assign-same-rule-sets-to-multiple-interfaces/m-p/2511834#M934539</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2014-06-18T13:03:26Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-assign-same-rule-sets-to-multiple-interfaces/m-p/2511835#M934540</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/acl_extended.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;H2 class="p_H_Head1"&gt;&lt;SPAN style="font-size: 12pt;"&gt;Information About Extended Access Lists&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;A name="wp1057103"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Access lists are used to control network access or to specify traffic for many features to act upon. An extended access list is made up of one or more access control entries (ACE) in which you can specify the line number to insert the ACE, the source and destination addresses, and, depending upon the ACE type, the protocol, the ports (for TCP or UDP), or the IPCMP type (for ICMP). You can identify all of these parameters within the access-list command, or you can use object groups for each parameter. This section describes how to identify the parameters within the command. To simplify access lists with object groups, see &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/objectgroups.html#wpxref14361"&gt;Chapter&amp;nbsp;16 "Configuring Object Groups."&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;A name="wp1077591"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;SPAN style="font-size: 8pt;"&gt;For TCP and UDP connections for both routed and transparent mode, you do not need an access list to allow returning traffic because the security appliance allows all returning traffic for established bidirectional connections. For connectionless protocols such as ICMP, however, the security appliance establishes unidirectional sessions, so you either need access lists to allow ICMP in both directions (by applying access lists to the source and destination interfaces), or you need to enable the ICMP inspection engine. The ICMP inspection engine treats ICMP sessions as bidirectional connections.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;A name="wp1077662"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;SPAN style="font-size: 8pt;"&gt;You can apply only one access list of each type (extended and EtherType) to each direction of an interface&lt;/SPAN&gt;. &lt;STRONG&gt;You can apply the same access lists on multiple interfaces.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 11:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-assign-same-rule-sets-to-multiple-interfaces/m-p/2511835#M934540</guid>
      <dc:creator>Nikolay Pestov</dc:creator>
      <dc:date>2016-08-09T11:51:19Z</dc:date>
    </item>
  </channel>
</rss>

