07-17-2014 05:09 AM - edited 03-11-2019 09:29 PM
Hello,
We didn't have any Firewall in our network, we recently implemented Cisco ASA (Context) firewall in our network with any any permit rule .
Our intension is to collect the source, destination, protocol & ports based on the traffic logs and then implement the access-lists , once we confirmed all the rule will added to the firewall we want remove any any permit rule .
I need some suggestion regarding this how we can proceed on this plan, any suggestions appreciated
Rajkumar
07-17-2014 10:55 AM
Hi Sind,
It is not a fair idea to create filters based on the logs in firewall. If so then you will be allowing unwanted traffic as well. So you need to identify the service by service from the business requirement. add the specific rule on top of permit ip any any and add the required rule on top of that... then monitor the hits for each access you have identified and provided.... then at last stage you can remove the permit ip any any from FW ACL.
Regards
Karthik
08-01-2014 10:33 PM
Thank you, I agree it is not fare idea however doyou have any specific steps to follow the identify the services as business users were not in position to provide any inforamation about the Services.
I need to find this out from the Firewall traffi rules only.
Any suggestions appreciated.
Regards
Rajkumar
08-01-2014 10:44 PM
Hi Rajkumar,
That is not the ideal way of doing... this will lead to a provisioning an unauthorized person to access for something he is not authorized to.
How many users do you have in your network? Try to categorize users based on their present authorization level of access.... say Team A users need to access everything... then you need to group them and provide full access..... Team B users need to be provided with only restricted access.... then group them and provide restricted access....
If your case is something like this.... all users need unrestricted intranet access and certain users alone requires internet acceess... then you can define rules accordingly....
Regards
Karthik
Regards
Karthik
08-01-2014 10:51 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide