ASA 5510 Configuration

I have a network where the main firewall is SA5510. I recently added a Microsoft TMG server to this network for caching and proxying. Presently all the local area network has access to internet. Please see this: (access-list ATM extended permit tcp any eq www). All the clients' gateway is ASA.

Well, now i want people to use web proxy (TMG) and ASA should allow only TMG server. what's the command to full fill this?

Please keep in mind that, One internal DNS server also plays as forwarder, so we need to give access the DNS server also in asa besides TMG, or TMG will take care of this? TMG is single interfaced.

Garry GlendownConnect With a Mentor Consulting and Network/Security SpecialistCommented:
Garry GlendownConsulting and Network/Security SpecialistCommented:
You narrow the access down to just the IP, e.g.

access-list ATM extended permit tcp any eq www

Do this also for the DNS or any other machine that requires direct access. You may also want to extended that to HTTPS ...
The easiest way is going in on ASDM and alter the rule, removing the /24, then add any IP in that rule.
abafadelAuthor Commented:
Thanks. What if i want to allow any protocol (regardless www. ftp, dns, etc)? instead of www at end, just add 'any'?

Garry GlendownConsulting and Network/Security SpecialistCommented:
Just leave the "eq www" away ... and possibly extend to "ip" instead of TCP (e.g. for UDP queries to DNS, etc.)
abafadelAuthor Commented:
So, it must be like this:

access-list ATM extended permit ip any

please correct if wrong
abafadelAuthor Commented:
