Dependable Auto Transport at EZAutoShippers.com
Tcp Traffic

Categories


Kindle: Amazon's New Wireless Reading Device

Tcp Traffic Article


 

How to Create and Manage Access-control Lists on Cisco Asa and Pix Firewalls

Copyright (c) 2008 Don R. Crawley

Access Control Lists (ACLs) are sequential lists of permit and deny conditions applied to traffic flows on a device interface. ACLs are based on various criteria including protocol type source IP address, destination IP address, source port number, and/or destination port number.

ACLs can be used to filter traffic for various purposes including security, monitoring, route selection, and network address translation. ACLs are comprised of one or more Access Control Entries (ACEs). Each ACE is an individual line within an ACL.

ACLs on a Cisco ASA Security Appliance (or a PIX firewall running software version 7.x or later) are similar to those on a Cisco router, but not identical. Firewalls use real subnet masks instead of the inverted mask used on a router. ACLs on a firewall are always named instead of numbered and are assumed to be an extended list.

The syntax of an ACE is relatively straight-forward:
Ciscoasa(config)#access-list name [line number] [extended] {permit | deny} protocol source_IP_address source_netmask [operator source_port] destination_IP_address destination_netmask [operator destination_port] [log [[disable | default] | [level]] [interval seconds]] [time-range name] [inactive]

Here's an example:
asa(config)# access-list demo1 permit tcp 10.1.0.0 255.255.255.0 any eq www
asa(config)# access-list demo1 permit tcp 10.1.0.0 255.255.255.0 any eq 443
asa(config)# show access-list demo1
access-list demo1; 2 elements
access-list demo1 line 1 extended permit tcp 10.1.0.0 255.255.255.0 any eq www
access-list demo1 line 2 extended permit tcp 10.1.0.0 255.255.255.0 any eq https

In the above example, an ACL called "demo1" is created in which the first ACE permits Tcp Traffic originating on the 10.1.0.0 subnet to go to any destination IP address with the destination port of 80 (www). In the second ACE, the same traffic flow is permitted for destination port 443. Notice in the output of the show access-list that line numbers are displayed and the extended parameter is also included, even though neither was included in the configuration statements.

You can deactivate an ACE without deleting it by appending the inactive option to the end of the line.

As with Cisco routers, there is an implicit "deny any" at the end of every ACL. Any traffic that is not explicitly permitted is implicitly denied.

**Editing ACLs and ACEs**

New ACEs are appended to the end of the ACL. If you want, however, to insert the new ACE at a particular location within the ACL, you can add the line number parameter to the ACE:

asa04(config)# access-list demo1 line 1 deny tcp host 10.1.0.2 any eq www
asa04(config)# show access-list demo1
access-list demo1; 3 elements
access-list demo1 line 1 extended deny tcp host 10.1.0.2 any eq www
access-list demo1 line 2 extended permit tcp 10.1.0.0 255.255.255.0 any eq www
access-list demo1 line 3 extended permit tcp 10.1.0.0 255.255.255.0 any eq https

Notice in the first line of the example above that an ACE is added at line one in the ACL. Notice in the output from the show access-list demo1 command that the new entry is added in the first position in the ACL and the former first entry becomes line number two.

You can remove an ACE from an ACL by preceding the ACE configuration statement with the modifier no, as in the following example:
Asa04(config)#no access-list demo1 deny tcp host 10.10.2 any eq www

In my next article, I'll show you how to use time-ranges to apply access-control lists only at certain times and/or on certain days. I'll also show you how to use object-groups with access-control lists to simplify ACL management by grouping similar components such as IP addresses or protocols together.


Don R. Crawley, CCNA-certified, is president and chief technologist at soundtraining.net, the Seattle training firm specializing in business skills and technical training for IT professionals. He works with IT pros to enhance their work, lives, and careers. For more information about soundtraining.net's accelerated Cisco ASA training, visit here.

Article Source: ArticlesBase.com


I need tcp traffic bidirectional port 5900?
Please help

Get the answers...


How do i unblock/enable ports for DHT/NAT for my torrent client (Azureus) when i have a router (WRT45G) setup?
In Azureus, the lights for NAT and DHT are always red (blocked/disabled)....instead of green, How Can I open these ports? I use Zone Alarm Pro, the these ports are already opened for UDP/TCP traffic.

Get the answers...


Is it possible to change firewall settings or bypass a proxy without administrator priviliges?
I'm trying to play a couple of games at work while it is slow but I can't connect because I'm assuming port 43594 is closed to TCP traffic. Is there any way to open that, or get around that somehow without admin status? Our network is monitored by a company called Websense I believe. And the proxy port is 8080.

Get the answers...

Related Tcp-traffic Videos


Next page: Monitor Apache


Bookmark/Share This Page:

ADD TO DEL.ICIO.US
ADD TO DIGG
ADD TO FURL
ADD TO NEWSVINE
ADD TO NETSCAPE
ADD TO REDDIT
ADD TO STUMBLEUPON
ADD TO TECHNORATI FAVORITES
ADD TO SQUIDOO
ADD TO WINDOWS LIVE
ADD TO YAHOO MYWEB
ADD TO ASK
ADD TO GOOGLE
ADD TO MAGNOLIA
ADD TO NING
ADD TO RAWSUGAR
ADD TO SPURL
ADD TO TAGTOOGA


Bookmark and Share

Recommended Products

Shop Official 2010 NFL Sideline Gear at FansEdge


Tcp Traffic News


Mobile Marketing on Track for Rapid Adoption in 2012 According to StrongMail ... - San Francisco Chronicle (press release)


MediaPost Communications

Mobile Marketing on Track for Rapid Adoption in 2012 According to StrongMail ...
San Francisco Chronicle (press release)
Mobile marketing programs and budgets are projected to increase, but many businesses are still held back by lack of strategy and resources Redwood City, CA (PRWEB) May 23, 2012 StrongMail, a leading provider of digital marketing solutions for email, ...
StrongMail Partners With Mobile Marketing Leader VeltiMarketWatch (press release)
Mobile Marketing Small But GrowingMediaPost Communications

all 19 news articles »

Read more...


Oracle Buys Vitrue For Social Marketing - InformationWeek


VentureBeat

Oracle Buys Vitrue For Social Marketing
InformationWeek
Vitrue could provide the social marketing hook to drive sales into RightNow and Oracle's CRM systems. Oracle will enter the social media publishing and campaign management market with the acquisition of Vitrue, announced Wednesday.
Oracle Buys VitrueMarketWatch (press release)
Oracle Buys Cloud Marketing Platform VitrueABC News
Oracle Buys Vitrue to Add Cloud Social Marketing to App PortfolioeWeek
Wall Street Journal
all 81 news articles »

Read more...


Marketo Introduces First Integrated Solution for Social Marketing Automation - MarketWatch (press release)


Marketo Introduces First Integrated Solution for Social Marketing Automation
MarketWatch (press release)
SAN FRANCISCO, May 23, 2012 /PRNewswire via COMTEX/ -- Marketo Summit 2012 -- In his keynote at Marketo Summit 2012 (#MUS12), Marketo President and CEO Phil Fernandez announced that Marketo is ushering in a new era of marketing automation with the ...
Marketo Wants To Add A Social Boost To Every Marketing CampaignTechCrunch
Marketo Takes Marketing Automation to Social MediaADOTAS

all 9 news articles »

Read more...


Senior Digital Marketers Meet for Best Practices Roundtable in San Jose - San Francisco Chronicle (press release)


Senior Digital Marketers Meet for Best Practices Roundtable in San Jose
San Francisco Chronicle (press release)
Roundtables will feature Email Marketing; Integrated Digital Marketing; Managing Digital Teams; Mobile Commerce; Online Conversion Rate & Optimization; Online PR, Buzz Monitoring and Reputation Management; SEO; Site Search, Ecommerce Optimization ...

and more »

Read more...


Saepio Puts Mobile Front and Center in Distributed Marketing Strategies - MarketWatch (press release)


Saepio Puts Mobile Front and Center in Distributed Marketing Strategies
MarketWatch (press release)
However, the question remains, how do marketers integrate mobile messaging into marketing strategies? Mobile messaging in a distributed marketing environment must be implemented from a marketing perspective that takes into consideration all possible ...
4 Innovative Strategies for Easier, Cheaper Localized MarketingSoftware Advice (blog)

all 6 news articles »

Read more...


Gilead Files European Marketing Application for Boosting Agent Cobicistat - MarketWatch (press release)


Gilead Files European Marketing Application for Boosting Agent Cobicistat
MarketWatch (press release)
FOSTER CITY, Calif., May 23, 2012 (BUSINESS WIRE) -- Gilead Sciences, Inc. (NASDAQ:GILD) announced today that the Marketing Authorisation Application (MAA) for cobicistat, submitted on April 26, 2012, has been validated by the European Medicines Agency ...
Gilead Sciences Says MAA For Cobicistat Validated By European Medicines AgencyNASDAQ

all 7 news articles »

Read more...


How the Internet has changed companies' marketing plans - Los Angeles Times


How the Internet has changed companies' marketing plans
Los Angeles Times
It wasn't that long ago when the marketing menu for businesses consisted of print, radio and television. But as the Internet took hold, and Americans began to spend larger and larger shares of their time online, businesses began to see the ...

and more »

Read more...



Neustar's UltraDNS-Global Managed DNS

Permalink: Tcp Traffic | | Copyright © 2012 trafficpals.com All Rights Reserved

  Home   Sitemap   Develop Your Domain Names