Solved

Importing multiple IPs and domains into a Cisco ACL via ASDM

Posted on 2013-06-26
6
1,742 Views
Last Modified: 2013-06-26
ASDM Version: 7.1(2)

Cisco Hardware:   ASA5510

Hey folks.  I need to import and blacklist a list of varied IP addresses and domains.  No traffic in from them, no traffic out to them.

My questions:

1. In what format, and inside what file type, can I import these individual domains and IP addresses all at the same time (as a network object, or... what)?

2. What is best practice (and how exactly do I) import this list into a rule?

Thanks for your attention.
0
Comment
Question by:Demolay
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 20

Expert Comment

by:rauenpc
ID: 39278161
I'm not very experienced with blocking domain names, but below is a good link on how it's done.

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940e04.shtml

As far as IP's go, I've never done a bulk import using ASDM nor do I believe that function specifically exists. The easiest way you will be able to get the results you want is to go with object groups. I would add an ACL line to your inbound and outbound ACL's for any taffic going to/from the object group. Then you just need to add all the ip's/networks to the object group and it will block them both directions. This can be done via command line or ASDM, but it is not considered a "bulk import".
0
 

Author Comment

by:Demolay
ID: 39278228
Unfortunately, the list is *very* long and entering them manually is out of the question.
0
 
LVL 20

Accepted Solution

by:
rauenpc earned 500 total points
ID: 39278655
With command line this shouldn't be too bad of a task. If you are uncomfortable with CLI, you could start off with ASDM to make the object group (and you only need to enter 1 object in the group initially), and then setup the ACL lines. From there you can copy/paste in CLI. You might need to get notepad out and do some edit/replace, or in some cases I've used a combination of excel and notepad in order to get additional text.
0
PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

 

Author Comment

by:Demolay
ID: 39278981
Great, that's helpful.  Can you point me towards a helpful CLI guide?
0
 
LVL 20

Expert Comment

by:rauenpc
ID: 39279304
for your case, it might be easier to post a portion of your configuration and we can show you how to make the right changes.

In the ASDM, go to tools --> command line interface
Do a single line command "show run | inc access-group|access-list"

Mask any entry that would identify the company with something like XXXX or xx.xx.xx.xx. This output will show us the ACL's in use and the interfaces they are applied and we can then show what it takes to make the ACL entries and object groups.
0
 

Author Closing Comment

by:Demolay
ID: 39280071
Thank  you!
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question