Creating Access list rule on ASA5510 using a domain name

Posted on 2009-03-30
Last Modified: 2012-05-06
I am needing to allow our Symantec AV Server through our ASA 5510 to download updates.  I am only wanting to allow the server out to the symantec site(s).  I contacted Symantec to get a list of IP Addresses they use for their definition downloads.  Symantec indicated they reference a domainname/url and they don't have a list of IP's to give out.  They indicated I only need to reference in our firewall and it will work.  How do I create an access-list rule in the ASA to reference
Question by:angie_lynn

Assisted Solution

egyptco earned 100 total points
ID: 24024124

such feature would have been great but i'm afraid I've never heard about it. on the asa you should allow ports 80, 21 and 443 ( from your AV Server to any destination in outside and you shouldn't have any problems with the update.
or try this solution with LUAU 

Accepted Solution

FWeston earned 400 total points
ID: 24029288
Unfortunately, I don't think PIX/ASA support what you're trying to do.  The liveupdate site looks like it's set up in a round-robin DNS configuration, so I'll list the following options in the order of most secure to least secure:

1) add access-lists permitting your internal AV server to access tcp ports 80/21/443 on the six IPs below
2) add a single access-list permitting your internal AV server to access tcp ports 80/21/443 on the network
3) add a single access-list permitting your internal AV server to access tcp ports 80/21/443 on any host

Option 2 is probably a pretty safe option that won't require you to update ACLs every month.

FYI - the IP addresses I currently see for are:,,,,, and

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question