Adding A Downloadable Ip Acl - Cisco 3.3 User Manual

For windows server version 3.3
Table of Contents

Advertisement

Downloadable IP ACLs

Adding a Downloadable IP ACL

User Guide for Cisco Secure ACS for Windows Server
5-10
Examples of Cisco devices that support downloadable IP ACLs are:
PIX Firewalls
VPN 3000-series concentrators
Cisco devices running IOS version 12.3(8)T or greater
An example of the format you should use to enter PIX Firewall ACLs in the ACL
Definitions box follows:
permit tcp any host 10.0.0.254
permit udp any host 10.0.0.254
permit icmp any host 10.0.0.254
permit tcp any host 10.0.0.253
An example of the format you should use to enter VPN 3000 ACLs in the ACL
Definitions box follows:
permit ip 10.153.0.0 0.0.255.255 host 10.158.9.1
permit ip 10.154.0.0 0.0.255.255 10.158.10.0 0.0.0.255
permit 0 any host 10.159.1.22
deny ip 10.155.10.0 0.0.0.255 10.159.2.0 0.0.0.255 log
permit TCP any host 10.160.0.1 eq 80 log
permit TCP any host 10.160.0.2 eq 23 log
permit TCP any host 10.160.0.3 range 20 30
permit 6 any host HOSTNAME1
permit UDP any host HOSTNAME2 neq 53
deny 17 any host HOSTNAME3 lt 137 log
deny 17 any host HOSTNAME4 gt 138
deny ICMP any 10.161.0.0 0.0.255.255 log
permit TCP any host HOSTNAME5 neq 80
For detailed ACL definition information, see the command reference section of
your device configuration guide.
Before You Begin
You should have already configured any NAFS that you intend to use in your
downloadable IP ACL.
Chapter 5
Shared Profile Components
78-16592-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Secure access control serverSecure acs

Table of Contents