Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,Has anyone had any issues with these rules allowing traffic they shouldn't be ? We've had this twice that we know of. The first time around someone added a rule that wasn't specific enough and didn't enable logging so there were lessons learned ...
Hi,I noticed that port scans had been querying all the internal hosts with bidirectional NATs defined which is obviously expected. But I also noticed that odd internal hosts that shouldn't be routable were also in scope on occasion. Further investi...
If the sites you want exposed to the public only listen on ports 81 & 444 then you could to this with a static NAT & just allow those ports through the firewall from the WAN to LAN ? Slightly less common ports so will prevent a little bit of sniffin...
You're right the encryption will stop the ASA from seeing the packet and therefore won't be able to dynamically open the ports. The passive FTP port range is configured on the server so you could contact whoever manages that, otherwise they tend to ...
They are access control rules that will need adding to your access control list, I presume the firewall is already configured and has ACLs you can add those rules to ? See the link below, remember to be specific and only allow the ports required to ...
Thanks, I have since tested this on a lab on an ASA and it behaves in exactly the same way. Happy to accept this as a solution, the more I thought about it the more sense it made and also sounded familiar. Thanks again for the explanation.
This is a dynamic unidirectional outbound Nat so there are no connections in the table inbound. Just many outbound that should allow traffic back in as per the state table, but I would argue only from ips that we have initiated connections with ?