Solved

Allow specific traffic through CISCO ASA

Posted on 2010-08-18
8
469 Views
Last Modified: 2012-05-10
HI

I need to know if there is a way to specify an allowed traffic to some clients through Cisco ASA.
for example I have inside and outside interfaces,on the inside interface the network ip is 192.168.1.0 .
I need to allow all clients to access internet except clients 180 and 190 to access only email through outlokk ; ports pop3 and smtp.

Will someone please help me?


THANKS IN ADVANCE
0
Comment
Question by:oamal2001
  • 3
  • 3
  • 2
8 Comments
 
LVL 10

Expert Comment

by:qbakies
ID: 33468975
Are 180 and 190 their IP addresses (192.168.1.180)?
0
 
LVL 5

Accepted Solution

by:
TechnicallyMaybe earned 500 total points
ID: 33468980
From what I understand, the clients at .180 and .190 only get access to smtp and pop3 and everyone else does not have any restrictions.
You would create access-lists on your inside interface.
Something like:
access-list inside permit tcp host 192.168.1.180 any eq smtp  <-- grant access to smtp from .180
access-list inside permit tcp host 192.168.1.180 eq pop3         <-- grant access to pop3 from .180
access-list inside deny tcp host 192.168.1.180 any         <-- prevent access to any other port on .180
access-list inside permit tcp host 192.168.1.190 any eq smtp   <-- grant access to smtp from .190
access-list inside permit tcp host 192.168.1.190 eq pop3          <-- grant access to pop3 from .190
access-list inside deny tcp host 192.168.1.190 any         <-- prevent access to any other port on .190
access-list inside permit tcp any any           <-- allow everyone access to every port

Since rules are processed from the top down and processing stops when a rule is matched, .180 and .190 will never make it to the bottom that grants unrestricted access but everyone else will.
0
 
LVL 10

Expert Comment

by:qbakies
ID: 33469028
Technically's access-list is correct but I would do access-list inside deny IP host 192.168.1.180 any instead of access-list inside deny TCP host 192.168.1.180 any.  This will make sure no traffic is allowed as opposed to only TCP traffic.  Do you know the CLI commands for applying the new access list to the inside interface?
0
 

Author Comment

by:oamal2001
ID: 33472542
Thanks TechnicallyMaybe I will test it and I will get back.
Thanks qbakies  I think it is the access group command,is that right?
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 

Author Comment

by:oamal2001
ID: 33472560
Is it better to do the last acces list with ip not tcp?

THANKS
0
 
LVL 10

Expert Comment

by:qbakies
ID: 33474124
Yes the last statement is should also be IP.  Command for applying this to your inside interface would be:

access-group <ACL NAME> in interface inside
0
 
LVL 5

Expert Comment

by:TechnicallyMaybe
ID: 33474431
Oops sorry, thanks qbakies!
0
 

Author Closing Comment

by:oamal2001
ID: 33574456
THANKS,It is working fine
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Routing VLANs 5 46
VLAN Tagged traffic 2 21
Cisco NBAR 6 17
EIGRP Configuration 2 14
When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This video discusses moving either the default database or any database to a new volume.

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now