{"id":545,"date":"2010-07-21T10:55:41","date_gmt":"2010-07-21T10:55:41","guid":{"rendered":"http:\/\/wiki.freeiz.com\/?p=545"},"modified":"2016-08-09T12:02:12","modified_gmt":"2016-08-09T12:02:12","slug":"cisco-asa-ftp-access-list","status":"publish","type":"post","link":"https:\/\/wiki-see.info\/wp\/2010\/07\/21\/cisco-asa-ftp-access-list\/","title":{"rendered":"Cisco ASA FTP Access-List"},"content":{"rendered":"<pre>ASA Version 7.2(2)\n!\nhostname ASA-AIP-CLI\ndomain-name corp.com\nenable password WwXYvtKrnjXqGbu1 encrypted\nnames\n!\ninterface Ethernet0\/0\n nameif Outside\n security-level 0\n ip address 192.168.1.2 255.255.255.0\n!\ninterface Ethernet0\/1\n nameif Inside\n security-level 100\nip address 10.1.1.1 255.255.255.0\n!\ninterface Ethernet0\/2\n nameif DMZ\n  security-level 50\n  ip address 172.16.1.12 255.255.255.0\n!\ninterface Ethernet0\/3\n no nameif\n no security-level\n no ip address\n!\ninterface Management0\/0\n  no nameif\n no security-level\n no ip address\n!\n<em>\n<span style=\"color: #0000ff;\">!--- Output is suppressed.<\/span>\n<\/em>\n<em>\n<span style=\"color: #0000ff;\">!--- Permit inbound FTP control traffic. <\/span>\n<\/em>\n<strong>access-list 100 extended permit tcp any host 192.168.1.5 eq ftp<\/strong>\n<em>\n<span style=\"color: #0000ff;\">!--- Permit inbound FTP data traffic.<\/span>\n<\/em>\n<strong>access-list 100 extended permit tcp any host 192.168.1.5 eq ftp-data<\/strong>\n!\n<em>\n<span style=\"color: #0000ff;\">!--- Command to redirect the FTP traffic received on IP 192.168.1.5\n!--- to IP 172.16.1.5.<\/span>\n<\/em>\n<strong>static (DMZ,outside) 192.168.1.5 172.16.1.5 netmask 255.255.255.255<\/strong>\n<strong>access-group 100 in interface outside<\/strong>\nclass-map inspection_default\n match default-inspection-traffic\n!\n!\npolicy-map type inspect dns preset_dns_map\n parameters\n  message-length maximum 512\n\n<strong>policy-map global_policy<\/strong>\n <strong>class inspection_default<\/strong>\n  inspect dns preset_dns_map\n  <strong>inspect ftp<\/strong>\n  inspect h323 h225\n  inspect h323 ras\n  inspect netbios\n  inspect rsh\n  inspect rtsp\n  inspect skinny\n  inspect esmtp\n  inspect sqlnet\n  inspect sunrpc\n  inspect tftp\n  inspect sip\n  inspect xdmcp\n!\n<em>\n<span style=\"color: #0000ff;\">!--- This command tells the device to\n!--- use the \"global_policy\" policy-map on all interfaces.<\/span>\n<\/em>\n<strong>service-policy global_policy global<\/strong>\n\nLAN Outbound FTP Access : <!-- #toc, .toc, .mw-warning { \tborder: 1px solid #aaa; \tbackground-color: #f9f9f9; \tpadding: 5px; \tfont-size: 95%; } #toc h2, .toc h2 { \tdisplay: inline; \tborder: none; \tpadding: 0; \tfont-size: 100%; \tfont-weight: bold; } #toc #toctitle, .toc #toctitle, #toc .toctitle, .toc .toctitle { \ttext-align: center; } #toc ul, .toc ul { \tlist-style-type: none; \tlist-style-image: none; \tmargin-left: 0; \tpadding-left: 0; \ttext-align: left; } #toc ul ul, .toc ul ul { \tmargin: 0 0 0 2em; } #toc .toctoggle, .toc .toctoggle { \tfont-size: 94%; }@media print, projection, embossed { \tbody { \t\tpadding-top:1in; \t\tpadding-bottom:1in; \t\tpadding-left:1in; \t\tpadding-right:1in; \t} } body { \tfont-family:'Times New Roman'; \tcolor:#000000; \twidows:2; \tfont-style:normal; \ttext-indent:0in; \tfont-variant:normal; \tfont-weight:normal; \tfont-size:12pt; \ttext-decoration:none; \ttext-align:left; } table { } td { \tborder-collapse:collapse; \ttext-align:left; \tvertical-align:top; } -->\n<div>\naccess-list inside extended permit tcp host 10.1.1.254 any eq ftp\n\n<strong>Create Object group in order to tidy config :<\/strong>\n\nobject-group service Bluecoatbypass tcp\n description Bypass for bluecoat server\n port-object eq echo\n port-object eq irc\n port-object eq ftp-data\n port-object range 3389 3389\n port-object eq domain\n port-object range 8080 8080\n port-object eq pop3\n port-object eq ftp\n port-object eq www\n port-object eq https\n port-object eq 1935\n port-object eq ssh\n!\n<strong>Create Access-list :<\/strong>\n<!-- ======================================================= -->access-list inside extended permit tcp host 10.1.1.254\nany object-group Bluecoatbypass<\/div>\n<strong>\nVerify :<\/strong>\nshow access-list | grep ftp | grep 10.1.1.254\nshow service-policy inspect ftp\nshow service-policy global<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>ASA Version 7.2(2) ! hostname ASA-AIP-CLI domain-name corp.com enable password WwXYvtKrnjXqGbu1 encrypted names ! interface Ethernet0\/0 nameif Outside security-level 0 ip address 192.168.1.2 255.255.255.0 ! interface Ethernet0\/1 nameif Inside security-level 100 ip address 10.1.1.1 255.255.255.0 ! interface Ethernet0\/2 nameif DMZ security-level 50 ip address 172.16.1.12 255.255.255.0 ! interface Ethernet0\/3 no nameif no security-level no ip [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[40,71,163,313],"class_list":["post-545","post","type-post","status-publish","format-standard","hentry","category-cisco-asa","tag-access-list","tag-asa-acl","tag-cisco-asa","tag-ftp"],"_links":{"self":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/comments?post=545"}],"version-history":[{"count":1,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/545\/revisions"}],"predecessor-version":[{"id":4736,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/545\/revisions\/4736"}],"wp:attachment":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/media?parent=545"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/categories?post=545"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/tags?post=545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}