cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
381
Views
0
Helpful
3
Replies

blocking inter network traffic to certain IP's on an ASA 5505

Doug-IVKS
Level 1
Level 1

Currently we are using an ASA 5505. What I need to accomplish, is I need to block all machines inside our network from reaching a certain few machines in the network. Unfortunately, I can't create a new Vlan to accomplish this, so I believe I'm going to have to accomplish this with access rules. Is this possible?   

3 Replies 3

Jon Marshall
Hall of Fame
Hall of Fame

If all the machines are in the same IP subnet you cannot use the ASA.

Can you give us some more details ie.what are the machines connected to, what is their default gateway, are they all in the same IP subnet ?

Jon

The machines in question are credit card machines that need to be separated from the rest of the network for compliance issues. They are all on the same subnet. 

All machines on the network use the ASA as their default gateway. 

I did just remember that I have a few RVS4000's that I could use to create new subnets for the credit card machines.

Would this course of action be possible? 

If they are all in the same subnet you can't use the ASA because devices in the same subnet don't use their default gateway to communicate.

You either need a new vlan for those machines or if your switch supports them private vlans would work.

What switch(es) are all the devices connected to ?

Jon