I can't write ACLs

I can't write ACLs

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
I can't write ACLs PL 06-26-2008
Posted by Andrew Lutov on June 26, 2008, 10:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello, PL!

P> interface Ethernet0/1
P> nameif inside
P> security-level 100
P> ip address 192.168.1.1 255.255.255.0
P> !
P> interface Ethernet0/2
P> nameif dmz1
P> security-level 2
P> ip address 192.168.2.1 255.255.255.0
P> !
P> access-list acl_outgoing extended deny ip any 192.168.2.0
P> 255.255.255.0
P> access-list acl_outgoing extended permit ip any any
P> !
P> access-group acl_outgoing in interface inside


ASA ?

--
А5 увидимся е2 ли



NMFall 20%
Posted by PL on June 27, 2008, 12:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Sorry! Yes, it's an ASA.

On Fri, 27 Jun 2008 09:16:54 +0700, "Andrew Lutov" <andrew_l @
newmail.ru> wrote:

>Hello, PL!
>
> P> interface Ethernet0/1
> P> nameif inside
> P> security-level 100
> P> ip address 192.168.1.1 255.255.255.0
> P> !
> P> interface Ethernet0/2
> P> nameif dmz1
> P> security-level 2
> P> ip address 192.168.2.1 255.255.255.0
> P> !
> P> access-list acl_outgoing extended deny ip any 192.168.2.0
> P> 255.255.255.0
> P> access-list acl_outgoing extended permit ip any any
> P> !
> P> access-group acl_outgoing in interface inside
>
>
>ASA ?


Posted by PL on June 27, 2008, 5:45 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Ok, so a day later, I finally figured it out... I was using Windows
Explorer to test connectivity, but apparently, once the SMB connection
is established on top IP, the ACL will no longer filter it until the
connection is deleted within Windows or the firewall is rebooted. Is
there another way to enforce the new ACL without these two methods? I
tried to reapply the ACL to the interface using "access-group" but
that didn't work.



>Trying to block access from "inside" to "dmz1"...
>
>interface Ethernet0/1
> nameif inside
> security-level 100
> ip address 192.168.1.1 255.255.255.0
>!
>interface Ethernet0/2
> nameif dmz1
> security-level 2
> ip address 192.168.2.1 255.255.255.0
>!
>access-list acl_outgoing extended deny ip any 192.168.2.0
>255.255.255.0
>access-list acl_outgoing extended permit ip any any
>!
>access-group acl_outgoing in interface inside
>
>Why am I still able to access host 192.168.2.2 from 192.168.1.7 ??


Posted by PacketU on June 27, 2008, 6:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You could try a clear xlate on the asa or pix. The issue is that the acl is
applied when the connection is set up with the three way handshake. After
that the ASA (Adaptive Security Algorithm) connection table will apply as
long as the protocol rules are being followed. I think a clear xlate would
clear this inromation and drop the connection without rebooting anything.
From a windows perspective, you may have also been able to do a net use /d
for each connection listed in a "net use" command until there are none to
the dmz host. Then a subsequent connection would perform a new three way
handshake.


> Ok, so a day later, I finally figured it out... I was using Windows
> Explorer to test connectivity, but apparently, once the SMB connection
> is established on top IP, the ACL will no longer filter it until the
> connection is deleted within Windows or the firewall is rebooted. Is
> there another way to enforce the new ACL without these two methods? I
> tried to reapply the ACL to the interface using "access-group" but
> that didn't work.
>
>
>
>>Trying to block access from "inside" to "dmz1"...
>>
>>interface Ethernet0/1
>> nameif inside
>> security-level 100
>> ip address 192.168.1.1 255.255.255.0
>>!
>>interface Ethernet0/2
>> nameif dmz1
>> security-level 2
>> ip address 192.168.2.1 255.255.255.0
>>!
>>access-list acl_outgoing extended deny ip any 192.168.2.0
>>255.255.255.0
>>access-list acl_outgoing extended permit ip any any
>>!
>>access-group acl_outgoing in interface inside
>>
>>Why am I still able to access host 192.168.2.2 from 192.168.1.7 ??
>



Similar ThreadsPosted
RANCID show run or write net? October 20, 2006, 4:04 pm
How to write on syslog which users access via RAS. January 5, 2006, 11:12 am
How to write on syslog which users access via RAS. January 5, 2006, 11:46 am
FLASH Write Error #5 on Aironet 350 November 20, 2006, 8:12 pm
After a successfully telnet I always can only write short commands August 7, 2004, 3:14 pm
I require a UK company / Individual to write me a config. - Willing to pay! December 4, 2006, 4:14 am
Typical Read/Write times for a TCAM February 15, 2007, 4:55 pm
cisco firmware images will not write to floppy May 13, 2008, 3:33 pm
Unable to write new file to NVRAM on 2522 June 10, 2008, 6:14 am
AS5350: Main Memory Write Bus Error Interrupt July 23, 2004, 5:04 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map