?
Solved

Allow specific traffic through CISCO ASA

Posted on 2010-08-18
8
Medium Priority
?
482 Views
Last Modified: 2012-05-10
HI

I need to know if there is a way to specify an allowed traffic to some clients through Cisco ASA.
for example I have inside and outside interfaces,on the inside interface the network ip is 192.168.1.0 .
I need to allow all clients to access internet except clients 180 and 190 to access only email through outlokk ; ports pop3 and smtp.

Will someone please help me?


THANKS IN ADVANCE
0
Comment
Question by:oamal2001
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
8 Comments
 
LVL 10

Expert Comment

by:qbakies
ID: 33468975
Are 180 and 190 their IP addresses (192.168.1.180)?
0
 
LVL 5

Accepted Solution

by:
TechnicallyMaybe earned 2000 total points
ID: 33468980
From what I understand, the clients at .180 and .190 only get access to smtp and pop3 and everyone else does not have any restrictions.
You would create access-lists on your inside interface.
Something like:
access-list inside permit tcp host 192.168.1.180 any eq smtp  <-- grant access to smtp from .180
access-list inside permit tcp host 192.168.1.180 eq pop3         <-- grant access to pop3 from .180
access-list inside deny tcp host 192.168.1.180 any         <-- prevent access to any other port on .180
access-list inside permit tcp host 192.168.1.190 any eq smtp   <-- grant access to smtp from .190
access-list inside permit tcp host 192.168.1.190 eq pop3          <-- grant access to pop3 from .190
access-list inside deny tcp host 192.168.1.190 any         <-- prevent access to any other port on .190
access-list inside permit tcp any any           <-- allow everyone access to every port

Since rules are processed from the top down and processing stops when a rule is matched, .180 and .190 will never make it to the bottom that grants unrestricted access but everyone else will.
0
 
LVL 10

Expert Comment

by:qbakies
ID: 33469028
Technically's access-list is correct but I would do access-list inside deny IP host 192.168.1.180 any instead of access-list inside deny TCP host 192.168.1.180 any.  This will make sure no traffic is allowed as opposed to only TCP traffic.  Do you know the CLI commands for applying the new access list to the inside interface?
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 

Author Comment

by:oamal2001
ID: 33472542
Thanks TechnicallyMaybe I will test it and I will get back.
Thanks qbakies  I think it is the access group command,is that right?
0
 

Author Comment

by:oamal2001
ID: 33472560
Is it better to do the last acces list with ip not tcp?

THANKS
0
 
LVL 10

Expert Comment

by:qbakies
ID: 33474124
Yes the last statement is should also be IP.  Command for applying this to your inside interface would be:

access-group <ACL NAME> in interface inside
0
 
LVL 5

Expert Comment

by:TechnicallyMaybe
ID: 33474431
Oops sorry, thanks qbakies!
0
 

Author Closing Comment

by:oamal2001
ID: 33574456
THANKS,It is working fine
0

Featured Post

Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Powerful tools can do wonders, but only in the right hands.  Nowhere is this more obvious than with the cloud.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question