C H A P T E R 18 Permitting Or Denying Network Access - Cisco FirePOWER ASA 5500 series Configuration Manual

Security appliance command line
Hide thumbs Also See for FirePOWER ASA 5500 series:
Table of Contents

Advertisement

Inbound and Outbound Access List Overview
You might want to use an outbound access list to simplify your access list configuration. For example,
if you want to allow three inside networks on three different interfaces to access each other, you can
create a simple inbound access list that allows all traffic on each inside interface (see
Figure 18-1
Permit from
See the following commands for this example:
hostname(config)# access-list INSIDE extended permit ip any any
hostname(config)# access-group INSIDE in interface inside
hostname(config)# access-list HR extended permit ip any any
hostname(config)# access-group HR in interface hr
hostname(config)# access-list ENG extended permit ip any any
hostname(config)# access-group ENG in interface eng
Cisco Security Appliance Command Line Configuration Guide
18-2
Inbound Access Lists
Security
appliance
Inside
ACL Inbound
any
to
any
Permit from
10.1.1.0/24
10.1.2.0/24
Web Server:
209.165.200.225
Outside
ACL Inbound
any
to
any
10.1.3.0/24
Chapter 18
Permitting or Denying Network Access
Eng
ACL Inbound
Permit from
any
to
any
Figure
18-1).
OL-10088-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Pix 500 seriesCisco asa 5500 series

Table of Contents