Solved

How do I create an extended ACL for an ASA to restrict outbound SMTP traffic?

Posted on 2009-04-01
2
479 Views
Last Modified: 2012-05-06
I had planned on adding the two access-list commands to the outbound access group, but my ASA doesn't like the eq at the end of the first command.

Access-list outbound extended permit ip 10.254.1.0 255.255.225.0 eq smtp
Access-list outbound extended deny ip any any eq smpt
0
Comment
Question by:guitar_dave
2 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
ID: 24041746
You need to use TCP for the protocol (not IP) and you forgot the destination (any).  At the end of the list add a "permit ip any any" to allow all other traffic or else the default action is to deny all.

access-list outbound extended permit tcp 10.254.1.0 255.255.225.0 any eq smtp
access-list outbound extended deny tcp any any eq smtp
access-list outbound extended permit ip any any
0
 

Author Closing Comment

by:guitar_dave
ID: 31565440
Thank you
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.
Learn how to create flexible layouts using relative units in CSS.  New relative units added in CSS3 include vw(viewports width), vh(viewports height), vmin(minimum of viewports height and width), and vmax (maximum of viewports height and width).

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now