cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
175
Views
0
Helpful
1
Replies

Cisco ASA Port vs Object in Access Ruloes

Mokhalil82
Level 4
Level 4

Hi

This might be an easy one but just confuses me slightly as I am just starting out configuring asa firewalls. 

When configuring an access rule, what different does it make for the source, if I choose the INSIDE interface or an object group which defines all the inside networks. 

 

Thanks

 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

The access list entries should use a group. You would only use the interface itself in an access list entry if you were controlling traffic to the interface itself.

Once you build an access list on an ASA, you then apply it to the necessary interfaces using the access-group command. i.e something like:

access-group inside_access_in_1 in interface inside

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

The access list entries should use a group. You would only use the interface itself in an access list entry if you were controlling traffic to the interface itself.

Once you build an access list on an ASA, you then apply it to the necessary interfaces using the access-group command. i.e something like:

access-group inside_access_in_1 in interface inside
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card