06-20-2018 12:50 PM - edited 02-21-2020 07:54 AM
So, I have the ASA 5505 Firewall. I generate an ACL to block three IP. Those IP are from outside and are generating fraffic with an internal server.
After aome hours I still get traffic from those IPs as you can see in the nex image:
The IP 181.174.99.146 should be blocked, but it is not. I will apreciate any explanation so I can understand why is this happening.
Sorry about my english.
Solved! Go to Solution.
06-20-2018 01:14 PM
I believe if the the traffic initiated from inside it still work, but the source coming from outside it should block.
depends on how you configured, since its object we can not see what is inside that group
better watch on Monitoring see is that allowed from outside to inside or inside to outside.
* After configure rule have you saved and published the config.
BB
06-20-2018 01:14 PM
I believe if the the traffic initiated from inside it still work, but the source coming from outside it should block.
depends on how you configured, since its object we can not see what is inside that group
better watch on Monitoring see is that allowed from outside to inside or inside to outside.
* After configure rule have you saved and published the config.
BB
06-20-2018 01:37 PM
06-20-2018 01:53 PM
Yes good catch. let me know how to goes.
BB
06-20-2018 01:57 PM
I've created new rules:
Do yo think I need a rule: permit: any - any in the outside interface? as I did in the inside interface?
06-20-2018 02:30 PM
Inside to outside is ok, but outside (un-trusted traffic coming in always bad - until there is a requirement for specific rule).
To make Granular and best practice always permit what required, and rest let it go to deny deny in the last rule
on both Inside and outside.
BB
 
					
				
				
			
		
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide