<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5520 rule for databsae network in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5520-rule-for-databsae-network/m-p/974850#M939141</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, you need to understand what flows in your network and how. &lt;/P&gt;&lt;P&gt;If you collect certain details and study of your application and DB software to understand their connection initiation and necessity, it will give you a better picture of flow map with port numbers. &lt;/P&gt;&lt;P&gt;Then according to this prepare access list on both interfaces.  Ports you need to open will depend on the application and DB software, not really on the OS type unless they have any independent communication requirement outside of the app and DB. While placing access lists you can always put a permit line between those two subnets and then deny any to any line. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 May 2008 04:03:10 GMT</pubDate>
    <dc:creator>kapish.mohole</dc:creator>
    <dc:date>2008-05-01T04:03:10Z</dc:date>
    <item>
      <title>ASA5520 rule for databsae network</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-rule-for-databsae-network/m-p/974847#M939136</link>
      <description>&lt;P&gt;Could anyone advice, if I have database servers subnetwork behind an ASA5520 box, (application servers do not behind the ASA5520), what rules I need add in, basically?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what if the servers are unix server and what if the servers are window server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any comments will be appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-rule-for-databsae-network/m-p/974847#M939136</guid>
      <dc:creator>julxu</dc:creator>
      <dc:date>2019-03-11T12:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5520 rule for databsae network</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-rule-for-databsae-network/m-p/974848#M939138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends what type of database, for example we have sql database, for apps to talk to sql database servers needing to cross firewall I opened tcp port 1433 which is the SQL tcp ports needed for client apps or servers needing  to talk to sql database server..  basically you need to find out what database is that you are running and what are their required tcp ports to be opened in firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Apr 2008 04:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-rule-for-databsae-network/m-p/974848#M939138</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-04-17T04:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5520 rule for databsae network</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-rule-for-databsae-network/m-p/974849#M939140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jorge, great thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;except certain ports, I also need to get something which unix box always do - alow all the communicate session which original issued by DB server itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you and other expert advice me how can I do on ACL? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 May 2008 02:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-rule-for-databsae-network/m-p/974849#M939140</guid>
      <dc:creator>julxu</dc:creator>
      <dc:date>2008-05-01T02:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5520 rule for databsae network</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-rule-for-databsae-network/m-p/974850#M939141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, you need to understand what flows in your network and how. &lt;/P&gt;&lt;P&gt;If you collect certain details and study of your application and DB software to understand their connection initiation and necessity, it will give you a better picture of flow map with port numbers. &lt;/P&gt;&lt;P&gt;Then according to this prepare access list on both interfaces.  Ports you need to open will depend on the application and DB software, not really on the OS type unless they have any independent communication requirement outside of the app and DB. While placing access lists you can always put a permit line between those two subnets and then deny any to any line. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 May 2008 04:03:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-rule-for-databsae-network/m-p/974850#M939141</guid>
      <dc:creator>kapish.mohole</dc:creator>
      <dc:date>2008-05-01T04:03:10Z</dc:date>
    </item>
  </channel>
</rss>

