<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: asa5520 ACL</title>
    <link>https://slinkov.ru/openforum/vsluhforumID6/725.html</link>
    <description>interface Ethernet0/2.7&lt;br&gt;vlan 216&lt;br&gt;nameif xxx-dc&lt;br&gt;security-level 100&lt;br&gt;ip address 172.17.4.1 255.255.255.248&lt;br&gt;object-group network xxx-distr&lt;br&gt;network-object 172.31.0.0 255.255.0.0&lt;br&gt;&lt;br&gt;route xxx-dc 172.31.0.0 255.255.0.0 172.17.4.2 2&lt;br&gt;&lt;br&gt;access-list acl-xxx-distr extended deny ip object-group xxx-distr any&lt;br&gt;&lt;br&gt;&lt;br&gt;access-group acl-xxx-distr in interface xxx-dc&lt;br&gt;&lt;br&gt;Трафик ходит, хотя не должен. Почему?&lt;br&gt;</description>

<item>
    <title>asa5520 ACL (Om)</title>
    <link>https://slinkov.ru/openforum/vsluhforumID6/725.html#4</link>
    <pubDate>Mon, 06 May 2013 09:44:46 GMT</pubDate>
    <description>&lt;br&gt;Phase: 1&lt;br&gt;Type: ROUTE-LOOKUP&lt;br&gt;Subtype: input&lt;br&gt;Result: ALLOW&lt;br&gt;Config:&lt;br&gt;Additional Information:&lt;br&gt;in 172.31.0.0 255.255.0.0 xxx-dc&lt;br&gt;&lt;br&gt;Phase: 2&lt;br&gt;Type: ACCESS-LIST&lt;br&gt;Subtype:&lt;br&gt;Result: DROP&lt;br&gt;Config:&lt;br&gt;Implicit Rule&lt;br&gt;Additional Information:&lt;br&gt;Forward Flow based lookup yields rule:&lt;br&gt;in id=0xd839b0a8, priority=11, domain=permit, deny=true&lt;br&gt;hits=0, user_data=0x5, cs_id=0x0, flags=0x0, protocol=0&lt;br&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;br&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;br&gt;&lt;br&gt;Result:&lt;br&gt;input-interface: xxx-dc&lt;br&gt;input-status: up&lt;br&gt;input-line-status: up&lt;br&gt;output-interface: xxx-dc&lt;br&gt;output-status: up&lt;br&gt;output-line-status: up&lt;br&gt;Action: drop&lt;br&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;br&gt;</description>
</item>

<item>
    <title>asa5520 ACL (Om)</title>
    <link>https://slinkov.ru/openforum/vsluhforumID6/725.html#3</link>
    <pubDate>Mon, 06 May 2013 09:44:25 GMT</pubDate>
    <description>1: 13:19:45.979227 802.1Q vlan#216 P0 172.31.1.18.60493 &amp;gt; 172.27.0.10.445: P 3467662171:3467662415(244) ack 256553634 win 571&lt;br&gt;2: 13:19:45.982203 802.1Q vlan#216 P0 172.27.0.10.445 &amp;gt; 172.31.1.18.60493: P 256553634:256553878(244) ack 3467662415 win 255&lt;br&gt;3: 13:19:45.983500 802.1Q vlan#216 P0 172.31.1.18.60493 &amp;gt; 172.27.0.10.445: P 3467662415:3467662621(206) ack 256553878 win 570&lt;br&gt;4: 13:19:45.987162 802.1Q vlan#216 P0 172.27.0.10.445 &amp;gt; 172.31.1.18.60493: . 256553878:256555258(1380) ack 3467662621 win 254&lt;br&gt;5: 13:19:45.987253 802.1Q vlan#216 P0 172.27.0.10.445 &amp;gt; 172.31.1.18.60493: P 256555258:256556058(800) ack 3467662621 win 254&lt;br&gt;6: 13:19:45.987986 802.1Q vlan#216 P0 172.31.1.18.60493 &amp;gt; 172.27.0.10.445: . ack 256556058 win 562&lt;br&gt;7: 13:19:45.988947 802.1Q vlan#216 P0 172.31.1.18.60493 &amp;gt; 172.27.0.10.445: P 3467662621:3467662713(92) ack 256556058 win 562&lt;br&gt;8: 13:19:45.991464 802.1Q vlan#216 P0 172.27.0.10.445 &amp;gt; 172.31.1.18.60493: P 256556058:256556186(128) ack 3467662713 win 254&lt;br&gt;9: 13:19:46.188115 802.1Q vlan#216 P0 1</description>
</item>

<item>
    <title>asa5520 ACL (Om)</title>
    <link>https://slinkov.ru/openforum/vsluhforumID6/725.html#2</link>
    <pubDate>Mon, 06 May 2013 09:14:28 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;&amp;gt; nameif xxx-dc &lt;br&gt;&amp;gt;&amp;gt; security-level 100 &lt;br&gt;&amp;gt;&amp;gt; ip address 172.17.4.1 255.255.255.248 &lt;br&gt;&amp;gt;&amp;gt; object-group network xxx-distr &lt;br&gt;&amp;gt;&amp;gt; network-object 172.31.0.0 255.255.0.0 &lt;br&gt;&amp;gt;&amp;gt; route xxx-dc 172.31.0.0 255.255.0.0 172.17.4.2 2 &lt;br&gt;&amp;gt;&amp;gt; access-list acl-xxx-distr extended deny ip object-group xxx-distr any &lt;br&gt;&amp;gt;&amp;gt; access-group acl-xxx-distr in interface xxx-dc &lt;br&gt;&amp;gt;&amp;gt; Трафик ходит, хотя не должен. Почему?&lt;br&gt;&amp;gt; Откуда и куда ходит ваш трафик?&lt;br&gt;&lt;br&gt;НА другие интерфейсы и сети.&lt;br&gt;</description>
</item>

<item>
    <title>asa5520 ACL (Merridius)</title>
    <link>https://slinkov.ru/openforum/vsluhforumID6/725.html#1</link>
    <pubDate>Tue, 30 Apr 2013 14:58:34 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt; vlan 216 &lt;br&gt;&amp;gt; nameif xxx-dc &lt;br&gt;&amp;gt; security-level 100 &lt;br&gt;&amp;gt; ip address 172.17.4.1 255.255.255.248 &lt;br&gt;&amp;gt; object-group network xxx-distr &lt;br&gt;&amp;gt; network-object 172.31.0.0 255.255.0.0 &lt;br&gt;&amp;gt; route xxx-dc 172.31.0.0 255.255.0.0 172.17.4.2 2 &lt;br&gt;&amp;gt; access-list acl-xxx-distr extended deny ip object-group xxx-distr any &lt;br&gt;&amp;gt; access-group acl-xxx-distr in interface xxx-dc &lt;br&gt;&amp;gt; Трафик ходит, хотя не должен. Почему?&lt;br&gt;&lt;br&gt;Откуда и куда ходит ваш трафик?&lt;br&gt;</description>
</item>

</channel>
</rss>
