3-2
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 3 Access Rules
Controlling Network Access
In transparent firewall mode, you can combine extended access rules, management access rules, and
EtherType rules on the same interface.
•
General Information About Rules, page 3-2
•
Extended Access Rules, page 3-4
•
General Information About Rules
This section describes information for both access rules and EtherType rules, and it includes the
following topics:
•
Interface Access Rules and Global Access Rules, page 3-2
•
Inbound and Outbound Rules, page 3-2
•
•
•
•
NAT and Access Rules, page 3-4
Interface Access Rules and Global Access Rules
You can apply an access rule to a specific interface, or you can apply an access rule globally to all
interfaces. You can configure global access rules in conjunction with interface access rules, in which
case, the specific inbound interface access rules are always processed before the general global access
rules. Global access rules apply only to inbound traffic.
Inbound and Outbound Rules
You can configure access rules based on the direction of traffic:
•
Inbound—Inbound access rules apply to traffic as it enters an interface. Global and management
access rules are always inbound.
•
Outbound—Outbound rules apply to traffic as it exits an interface.
Note
“Inbound” and “outbound” refer to the application of an ACL on an interface, either to traffic entering
the ASA on an interface or traffic exiting the ASA on an interface. These terms do not refer to the
movement of traffic from a lower security interface to a higher security interface, commonly known as
inbound, or from a higher to lower interface, commonly known as outbound.
An outbound ACL is useful, for example, if you want to allow only certain hosts on the inside networks
to access a web server on the outside network. Rather than creating multiple inbound ACLs to restrict
access, you can create a single outbound ACL that allows only the specified hosts. (See the following
figure.) The outbound ACL prevents any other hosts from reaching the outside network.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...