cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1100
Views
0
Helpful
3
Replies

Cisco ASA Outside Interface (1 outgoing rule)

Matt S
Level 1
Level 1

Do I need to configure access list rules for the outside interface outbound traffic?

Right now I have one configuration on the Outside interface 

Firewall# sh run | i outside_access_out
access-list outside_access_out extended permit object-group DM_INLINE_SERVICE_4 any any
access-list outside_access_out_1 extended permit object-group DM_INLINE_SERVICE_8 any4 any4
access-group outside_access_out_1 out interface outside

1 Accepted Solution

Accepted Solutions

In general yes I would say it is not really necessary in most cases.

Jon

View solution in original post

3 Replies 3

Jon Marshall
Hall of Fame
Hall of Fame

It is up to you really and how you want to control your traffic.

In my experience the most common acl is the one applied inbound to the outside interface but that doesn't mean you cannot use acls in other directions.

Is there something specific you were trying to achieve ?

Jon

There isn't anything specifically; I am just trying to follow best practice I guess. So would you say that normally the outside outbound isn't really necessary to configure unless explicitly trying to block or permit something?

In general yes I would say it is not really necessary in most cases.

Jon

Review Cisco Networking for a $25 gift card