cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1307
Views
0
Helpful
2
Replies

Firewall Policy/Zones ASA 525X

AZKhan
Level 1
Level 1

Hello experts,

I have recently moved from Juniper(JunOS/Netscreen) based firewall environment and joined a department with Cisco setup. My task is to configure ASA 5525X firewalls to control traffic  flow between servers and also towards Internet. 
In Juniper, i have done this with Firewall Policies controlling traffic between Zones. Also Intra-Zone and Inter-Zone traffic restriction. Address-books used to define single IP/ or multiple IP's. 

In Juniper, we have done this as follows

set security policies from-zone Zone-Name to-zone Zone-Name policy Policy-Name match source-address Src-Adres
set security policies from-zone Zone-Name to-zone Zone-Name policy Policy-Name match destination-address Src-Adres
set security policies from-zone Zone-Name to-zone Zone-Name policy Policy-Name match application any
set security policies from-zone Zone-Name to-zone Zone-Name policy Policy-Name then permit


My question is,  How to get this done in Cisco ?

Defining zones?

Assigning interfaces to zone?

creating Address books?

creating policies with source/destination zone and source/destination address-books?

identifying particular ports within policies ?

Action deny/permit?

 

 

 

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

here is the guide to undertstand how ASA you can do this :

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/general/asa-general-cli/interface-zones.html#65622

 

 

in the document high level give you information, how you can do same way you can also have different zones inside and you can make policies(ACL) who required what access.

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

@balaji.bandi , thankx for reply, but in my case, i am unable to see any commands relevant to zone. ASA5525-X with Firepower services. No commands in CLI to configure zones. Is there any issue with ASA image?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card