<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic access-list question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724809#M999450</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should apply it on the outside interface access-list. So &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list in deny tcp host "bad ip address1" host 192.168.254.21 eq ftp &lt;/P&gt;&lt;P&gt;access-list in deny tcp host "bad ip address2" host 192.168.254.21 eq ftp &lt;/P&gt;&lt;P&gt;etc.. for bad ip addresses&lt;/P&gt;&lt;P&gt;access-list in permit tcp any host 192.168.254.1 eq ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Know what you mean about things taking longer to sink in &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 25 Mar 2007 01:47:27 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-03-25T01:47:27Z</dc:date>
    <item>
      <title>Basic access-list question</title>
      <link>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724808#M999448</link>
      <description>&lt;P&gt;Forgive me for such a basic question...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently allow ftp access from my outside interface to the server on my inside interface:&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.254.21 192.168.0.60 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list in permit tcp any host 192.168.254.21 eq ftp&lt;/P&gt;&lt;P&gt;access-group in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I don't like restricting based on IP address, but I have noticed 2 or 3 IP addresses (that seem to be static) that are attacking my ftp server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I write my access-list 'deny' statement for those IP addresses, am I going to apply it to the outside interface or the inside interface; as I currently allow everyone to access my ftp server from my outside interface...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In what order are access-lists evaluated?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(I'm 40 something and some things are not sinking in as quickly as when I was 20 something) &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724808#M999448</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2019-03-11T09:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Basic access-list question</title>
      <link>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724809#M999450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should apply it on the outside interface access-list. So &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list in deny tcp host "bad ip address1" host 192.168.254.21 eq ftp &lt;/P&gt;&lt;P&gt;access-list in deny tcp host "bad ip address2" host 192.168.254.21 eq ftp &lt;/P&gt;&lt;P&gt;etc.. for bad ip addresses&lt;/P&gt;&lt;P&gt;access-list in permit tcp any host 192.168.254.1 eq ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Know what you mean about things taking longer to sink in &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Mar 2007 01:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724809#M999450</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-25T01:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Basic access-list question</title>
      <link>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724810#M999452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I might be over complicating things, but, the ACL currently letting all ftp traffic in on my outside interface is already in place.&lt;/P&gt;&lt;P&gt;Do I need to first delete this rule, go back write my 'deny' ACLs, and then re-add my permit rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or can I just add the deny rule(s) to my production PIX?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Mar 2007 02:07:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724810#M999452</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2007-03-25T02:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: Basic access-list question</title>
      <link>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724811#M999453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The denies must be before the permit any or they won't do anything. It goes from the top down and stops at the first match.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Mar 2007 03:27:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724811#M999453</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-25T03:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Basic access-list question</title>
      <link>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724812#M999454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nothing like your boss coming to you one day and saying, "Here's a PIX. Get it working by Monday."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You the man (or woman...or tech)acomiskey! &lt;/P&gt;&lt;P&gt;YOU and your help is always much appreciated!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Mar 2007 03:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-access-list-question/m-p/724812#M999454</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2007-03-25T03:53:11Z</dc:date>
    </item>
  </channel>
</rss>

