11-11-2016 07:49 AM - edited 03-12-2019 01:31 AM
Hi,
Is there any way I could create a big sip access list and allow ports and IP address for only Voice Vlan on ASA 5505?
18.xx.xx.xx TCP 80,443, 8011
18.xx.xx.xx TCP 80,443, 8011
18.xx.xx.xx TCP 80,443, 8011
18.xx.xx.xxx TCO443
18.xxxx.xxx TCP5222
80.xx.xx.xx
17.xx.xx.xx UDP123
78.xx.xx.xx UDP123
89.xx.xx.xx TCP380
8.xx.xx.xx TCP389
12.34.44.44 UDP5060,TCP5080
12.23.32.44 UDP5060,TCP5080
56.65.55.44 UDP10000-60000
38.54.33.33 UDP 10000-60000
Thanks,
11-12-2016 07:09 AM
hi,
you can create service objects.
see helpful link:
http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/acl_objects.html#56437
11-12-2016 07:52 AM
Thanks John. How can I only apply to one subnet /vlan?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide