[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Allow specific traffic through CISCO ASA

Posted on 2010-08-18
8
Medium Priority
?
487 Views
Last Modified: 2012-05-10
HI

I need to know if there is a way to specify an allowed traffic to some clients through Cisco ASA.
for example I have inside and outside interfaces,on the inside interface the network ip is 192.168.1.0 .
I need to allow all clients to access internet except clients 180 and 190 to access only email through outlokk ; ports pop3 and smtp.

Will someone please help me?


THANKS IN ADVANCE
0
Comment
Question by:oamal2001
  • 3
  • 3
  • 2
8 Comments
 
LVL 10

Expert Comment

by:qbakies
ID: 33468975
Are 180 and 190 their IP addresses (192.168.1.180)?
0
 
LVL 5

Accepted Solution

by:
TechnicallyMaybe earned 2000 total points
ID: 33468980
From what I understand, the clients at .180 and .190 only get access to smtp and pop3 and everyone else does not have any restrictions.
You would create access-lists on your inside interface.
Something like:
access-list inside permit tcp host 192.168.1.180 any eq smtp  <-- grant access to smtp from .180
access-list inside permit tcp host 192.168.1.180 eq pop3         <-- grant access to pop3 from .180
access-list inside deny tcp host 192.168.1.180 any         <-- prevent access to any other port on .180
access-list inside permit tcp host 192.168.1.190 any eq smtp   <-- grant access to smtp from .190
access-list inside permit tcp host 192.168.1.190 eq pop3          <-- grant access to pop3 from .190
access-list inside deny tcp host 192.168.1.190 any         <-- prevent access to any other port on .190
access-list inside permit tcp any any           <-- allow everyone access to every port

Since rules are processed from the top down and processing stops when a rule is matched, .180 and .190 will never make it to the bottom that grants unrestricted access but everyone else will.
0
 
LVL 10

Expert Comment

by:qbakies
ID: 33469028
Technically's access-list is correct but I would do access-list inside deny IP host 192.168.1.180 any instead of access-list inside deny TCP host 192.168.1.180 any.  This will make sure no traffic is allowed as opposed to only TCP traffic.  Do you know the CLI commands for applying the new access list to the inside interface?
0
Become a Leader in Data Analytics

Gain the power to turn raw data into better business decisions and outcomes in your industry. Transform your career future by earning your MS in Data Analytics. WGU’s MSDA program curriculum features IT certifications from Oracle and SAS.  

 

Author Comment

by:oamal2001
ID: 33472542
Thanks TechnicallyMaybe I will test it and I will get back.
Thanks qbakies  I think it is the access group command,is that right?
0
 

Author Comment

by:oamal2001
ID: 33472560
Is it better to do the last acces list with ip not tcp?

THANKS
0
 
LVL 10

Expert Comment

by:qbakies
ID: 33474124
Yes the last statement is should also be IP.  Command for applying this to your inside interface would be:

access-group <ACL NAME> in interface inside
0
 
LVL 5

Expert Comment

by:TechnicallyMaybe
ID: 33474431
Oops sorry, thanks qbakies!
0
 

Author Closing Comment

by:oamal2001
ID: 33574456
THANKS,It is working fine
0

Featured Post

Get Certified for a Job in Cybersecurity

Want an exciting career in an emerging field? Earn your MS in Cybersecurity and get certified in ethical hacking or computer forensic investigation. WGU’s MSCSIA degree program was designed to meet the most recent U.S. Department of Homeland Security (DHS) and NSA guidelines.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question