<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Subinterface Access-List Application in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920450#M973757</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where exactly in the ASDM are you referring to? There doesn't seem to be a column for source port on the config -&amp;gt; security policy page, only destination port.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Oct 2007 12:18:51 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-10-11T12:18:51Z</dc:date>
    <item>
      <title>ASA Subinterface Access-List Application</title>
      <link>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920447#M973751</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had a situation where traffic needed to be blocked from one subinterface on the ASA to another, Security-level was setup the same with appropriate NAT and intra security level permissions. The thing was that the ACL needed to be placed signifying source port as opposed to destination port. When i applied the ACL to the subinterface i wanted to secure, nothing worked. I then checked ASDM and the output looked strange (no source ports were being listed).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess my question is can you limit traffic by source ports on an ASA using extended access-lists inbound to a subinterface that will scrutinize traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My subif would be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int f0/0.5&lt;/P&gt;&lt;P&gt;ip address 150.100.10.1&lt;/P&gt;&lt;P&gt;nameif dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ch permit tcp host 150.100.10.42 eq 4200 host 10.33.1.47 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group ch in interface dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this access-list allow tcp traffic from 150.100.10.42 on port 4200 to any tcp port on 10.33.1.47 and deny all others?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920447#M973751</guid>
      <dc:creator>nathancielieska</dc:creator>
      <dc:date>2019-03-11T11:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Subinterface Access-List Application</title>
      <link>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920448#M973752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it should.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2007 12:11:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920448#M973752</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-10-11T12:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Subinterface Access-List Application</title>
      <link>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920449#M973755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the response, much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a followup does ASDM not like to display source ports when viewing the ACL in ASDM utility?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2007 12:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920449#M973755</guid>
      <dc:creator>nathancielieska</dc:creator>
      <dc:date>2007-10-11T12:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Subinterface Access-List Application</title>
      <link>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920450#M973757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where exactly in the ASDM are you referring to? There doesn't seem to be a column for source port on the config -&amp;gt; security policy page, only destination port.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2007 12:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920450#M973757</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-10-11T12:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Subinterface Access-List Application</title>
      <link>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920451#M973758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thats exactly where i was looking, just thought it was strange.. thank you for your responses and their prompt nature&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2007 12:46:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-subinterface-access-list-application/m-p/920451#M973758</guid>
      <dc:creator>nathancielieska</dc:creator>
      <dc:date>2007-10-11T12:46:12Z</dc:date>
    </item>
  </channel>
</rss>

