ASA 8.4 cleaning using Network Configuration and Service objects

Hello

As most of you know, firewall configurations can growth in order to be large and complex, making them difficult to understand and difficult to change.

I have a cleaning using network firewall configuration and Service objects and groups of objects running from 8.4 who I want to. This ASA (8.4) has over 30 Web Server VM deployed behind each with the same basic configuration: one to the outside inside the IP address and port mapping (x.x.x.x:ftp to y.y.y.y:ftp, etc.) by using the following well known ports: FTP, 80, 443, 3389.

Examples of my existing configuration:

network of the Y.Y.Y.Y_FTP object

Home y.y.y.66

NAT (inside, outside) Static X.X.X.66 tcp ftp ftp service

network of the Y.Y.Y.Y_WWW object

Home y.y.y.66

NAT (inside, outside) Static X.X.X.66 tcp http http service

network of the Y.Y.Y.Y_HTTPS object

Home y.y.y.66

NAT (inside, outside) Static X.X.X.66 tcp 443 443 service

network of the Y.Y.Y.Y_RDP object

Home y.y.y.66

NAT (inside, outside) static service tcp 3389 3389 X.X.X.66

outside_in list extended access permit tcp any host y.y.y.66 eq ftp

outside_in list extended access permit tcp any host y.y.y.66 eq www

outside_in list extended access permit tcp any host y.y.y.66 eq 3389

outside_in list extended access permit tcp any host y.y.y.66 eq 443

The entries above for each port have to do whenever a new virtual machine is deployed behind the firewall.

Here's my ACE project and entered the object-group service to clean up configuration.

object-group service WWW_FTP

Description access FTP HTTP

the tcp destination eq ftp service object

the purpose of the tcp destination eq ftp service - data

the purpose of the service tcp destination eq www

object-group service WWW_FTP_RDP

Description access FTP RPD WWW

the tcp destination eq ftp service object

the purpose of the tcp destination eq ftp service - data

the purpose of the service tcp destination eq www

the destination eq 3389 tcp service object

object-group service WWW_FTP_RDP_SSH

Description access WWW RDP SSH FTP

the tcp destination eq ftp service object

the purpose of the tcp destination eq ftp service - data

the purpose of the service tcp destination eq www

the destination eq 443 tcp service object

the destination eq 3389 tcp service object

object-group service RDP_SSH

Access SSH RDP description

the destination eq 443 tcp service object

the destination eq 3389 tcp service object

object-group service RDP_SSH_FTP

Access SSH FTP RDP description

the destination eq 443 tcp service object

the destination eq 3389 tcp service object

the tcp destination eq ftp service object

the purpose of the tcp destination eq ftp service - data

object-group service RDP_FTP

Access FTP RDP description

the destination eq 3389 tcp service object

the tcp destination eq ftp service object

the purpose of the tcp destination eq ftp service - data

outside_in list extended access allowed object-group WWW_FTP_RPD any host Y.Y.Y.Y

outside_in list extended access allowed object-group WWW_FTP_RDP_SSH any host Y.Y.Y.Y

outside_in list extended access allowed object-group WWW_FTP any host Y.Y.Y.Y

outside_in list extended access allowed object-group RDP_FTP any host Y.Y.Y.Y

outside_in list extended access allowed object-group RDP_SSH_FTP any host Y.Y.Y.Y

outside_in list extended access allowed object-group RDP_SSH any host Y.Y.Y.Y

The challenge lies in the consolidation of the network object entries that follow into something more condensed as the entries in the object-group service.

network of the Y.Y.Y.Y_FTP object

Home y.y.y.66

NAT (inside, outside) Static X.X.X.66 tcp ftp ftp service

network of the Y.Y.Y.Y_WWW object

Home y.y.y.66

NAT (inside, outside) Static X.X.X.66 tcp http http service

network of the Y.Y.Y.Y_HTTPS object

Home y.y.y.66

NAT (inside, outside) Static X.X.X.66 tcp 443 443 service

network of the Y.Y.Y.Y_RDP object

Home y.y.y.66

NAT (inside, outside) static service tcp 3389 3389 X.X.X.66

Any help is greatly appreciated!

Hello

I'm afraid that the only part of the configuration you can really change and make more condenced is configurations ACL using configurations different ' object-group ' .

Of course, you can also create a "object-group" for all servers that need the same ports open to further reduce the lines of actual configurations in the configuration of the CLI.

However,.

Regarding NAT configurations there is unfortunately no way to reduce the amount of required configurations if you use Static PAT (Port Forward) for servers. There is no way yet to ports in group for "nat" configurations.

My question is, you have public IP addresses less at your disposal compared with the amount of different servers in your network behind the ASA?

If you have a public IP address dedicated to each server in the network, then I suggest to use static NAT instead of static PAT. It's about the only way that the NAT configuration could be minimized.

-Jouni

Tags: Cisco Security

Similar Questions

  • Database objects can be replicated using Oracle Streams and which object cannot be replicated?

    Hi Experts,

    I need clarification on the sub questions,.


    Database objects can be replicated using Oracle Streams and which object cannot be replicated?

    How can we check that what schema and objects are used streams replication and which schema and objects is not used in the replication stream?

    Thanks in advance.

    Select *.
    of dba_streams_unsupported
    where owner | '.' || table_name (...)

    order by 1, 2, 3;

  • Using networks, organization and network outdoor pools

    Hello

    I've been messing around all day trying to get this to work. Currently, we use LabManager and are now moving to vCloud Director.

    How we currently have LabManager to installation:

    The configuration is closed.

    The 192.168.0.20 configuration ip address range - 192.168.0.30 (these are static ip addresses, the machines use to communicate with each other)

    It is then natted to VLAN800 and 10.1.180.10 of the IP - 10.1.180.200 (this one ip pool, we use these IPS to RDP and connect to this configuration of our work desktop computers)

    This configuration is not accessible through the internet (public network)

    For some reason I can't get the same configuration in vCD. Y does it have any chance someoen could post some photos of what the external networks, organization and network pools should look like for installation. I tried every combination I can think but he can't get the works.

    Help, please!

    Thank you!

    Hello

    The tab system-> cloud resources (left menu)-> organization VDC (left menu)-> 'your ORG name' - right click-> network Pool tab

    You have selected your network pool here?

  • WiFi stop working when 9.2.1 upgrade... A does restore the network configuration and still does not!

    from one day to the next my phone is suddenly being updated to 9.2.1. Since then my wifi was NOT working period. Have excellent wifi signal and still absolutely nothing. I reset the network settings and nothing works. Never been a problem until this 9.2.1 update

    I have the same problem after updating ios 9.2.1

  • Network configuration and the Parental control and Powerline wireless Extender

    I'm looking at one of them to help to get wifi in my addiction.

    I need this on the same 'network' as my Nighthawk AC1750 router because I use it with wireless security cameras.

    Two questions about wifi created from extender by current holder:

    1. can I configure wifi with the same name and password powerline network is the 'same' as the network from the router?

    2. the standard OpenDNS parental control on the Nighthawk router will work when connected to wifi extender Cpl?

    zr8000 wrote:

    I'm looking at one of them to help to get wifi in my addiction.

    I need this on the same 'network' as my Nighthawk AC1750 router because I use it with wireless security cameras.

    Two questions about wifi created from extender by current holder:

    1. can I configure wifi with the same name and password powerline network is the 'same' as the network from the router?

    Yes.

    2. the standard OpenDNS parental control on the Nighthawk router will work when connected to wifi extender Cpl?

    Yes, your Nighthawk will still work as the DHCP server for the network and, therefore, point devices on the OpenDNS servers.

  • How to configure the service objective for use minimization?

    Hi all

    I worked on a minimization problem (for more details, see this post).  I figured out how to run an unconstrained minimization, but can not quite understand why my thread objective function remains broken.  Here is a screenshot:

    Any ideas?

    I understand not under this main VI of the example, a subroutine that performs the minimization and a subroutine that is called when the minimization.  As it seems that I am limited to 3 accessories, I will add some sample data to the first answer I will generate.

    Thank you very much

    RipRock

    Hi all

    I just thought of it.  For those who may be confused, as well, the answer is: follow the directions!  RTFM!  In other words, if you use the template provided to the function of labview\vi.lib\gmath\NumericalOptimization\ucno_objective template.vit, rather than recreate the code in the example, it works.

    Sorry for these positions - and thank you for your attention,

    RipRock

  • How to configure a network printer and network drive in Windows 7?

    * Original title: cohen * address email is removed from the privacy *.

    having trouble mapping.  naming and configuration of a network in windows 7 pro drive. I am connected via a wireless network and also try to use my jet of office of hp as a network printer I need to know how configure that as well

    Hello

    I would like you to check out the links and check if it helps the network configuration and the network printer.

    http://Windows.Microsoft.com/en-CA/Windows/create-shortcut-map-network-drive#1TC=Windows-7

    http://Windows.Microsoft.com/en-CA/Windows/install-printer-home-network#1TC=Windows-7

    http://Windows.Microsoft.com/en-CA/Windows/install-printer#install-printer=Windows-7

    http://Windows.Microsoft.com/en-in/Windows/network-connection-problem-help#network-problems=Windows-7&V1H=win81tab1&V2H=win7tab3&V3H=winvistatab1&v4h=winxptab1

    Hope this information helps. If you have any questions, please let us know.

  • set up a home network with the PC using xp vista and windows 7

    I need to know how confugure my desktop vista and xp desktop and cell phone with my computer laptop windows 7.  detailed with inustrictions or links please.

    Hello

    You plug the computer via the network to a router or a switch card, and configuring their file sharing.

    ---------------------

    Win7 when configured on the peer-to-peer network has three types of configurations of sharing.

    Group residential network = only works between Win 7 computers. This type of configuration, it is very easy to entry level users to start sharing network.

    Working network = fundamentally similar to previous methods of sharing that allow you to control what, how and to whom the records would be shared with.

    Public share
    = network Public (as Internet Café) in order to reduce security risks.

    For the best newspaper of the results of each computer screen system and together all computers on a network of the same name, while each computer has its own unique name.

    http://www.ezlan.NET/Win7/net_name.jpg

    Make sure that the software firewall on each computer allows free local traffic. If you use 3rd party Firewall on, Vista/XP Firewall Native should be disabled, and the active firewall has adjusted to your network numbers IP on what is sometimes called the Zone of confidence (see part 3 firewall instructions

    General example, http://www.ezlan.net/faq#trusted
    Please note that some 3rd party software firewall continue to block the same aspects it traffic Local, they are turned Off (disabled). If possible, configure the firewall correctly or completely uninstall to allow a clean flow of local network traffic. If the 3rd party software is uninstalled, or disables, make sure Windows native firewall is active .

    ------------------------------

    If your network consists only of Win 7 and you want a simple network, use it.

    http://Windows.Microsoft.com/en-us/Windows7/help/videos/sharing-files-with-HomeGroup

    After you have configured the homegroup, scroll to the bottom for the Permission/security section.

    -----------------------------

    Win 7 networking with other version of Windows as a work network.

    In the center of the network, by clicking on the type of network opens the window to the right.

    Choose your network type. Note the check box at the bottom and check/uncheck depending on your needs.

    http://www.ezlan.NET/Win7/net_type.jpg

    Win 7 - http://windows.microsoft.com/en-us/windows7/Networking-home-computers-running-different-versions-of-Windows

    Win 7 network sharing folder specific work - http://www.onecomputerguy.com/windows7/windows7_sharing.htm

    Vista file and printer sharing - http://technet.microsoft.com/en-us/library/bb727037.aspx

    Windows XP file sharing - http://support.microsoft.com/default.aspx?scid=kb;en-us;304040
    Sharing printer XP - http://www.microsoft.com/windowsxp/using/networking/expert/honeycutt_july2.mspx

    Setting Windows native firewall for sharing XP - http://support.microsoft.com/kb/875357
    Windows XP Patch for sharing with Vista (no need for XP - SP3) - http://support.microsoft.com/kb/922120

    When you have finished the configuration of the system, it is recommended to restart everything the router and all computers involved.

    -------------

    If you have authorization and security problems, check the following settings.

    Point to a folder that wants to share do right click and choose Properties.

    In the properties

    Click on the Security tab shown in the bellows of the photo on the right) and verify that users and their permissions (see photo below Centre and left) are configured correctly. Then do the same for the authorization tab.

    This screen shot is to Win 7, Vista menus are similar.

    http://www.ezlan.NET/Win7/permission-security.jpg

    The Security Panel and the authorization Panel, you need to highlight each user/group and consider that the authorization controls are verified correctly.

    When everything is OK, restart the network (router and computer).

    * Note . The groups and users listed in the screen-shoot are just an example. Your list will focus on how your system is configured.

    * Note . There must be specific users. All means all users who already have an account now as users. This does not mean everyone who feel they would like to connect.

    ---------------------

    * Note. Some of the processes described above are made sake not for Windows, but to compensate for different routers and how their firmware works and stores information about computers that are networked.

    Jack-MVP Windows Networking. WWW.EZLAN.NET

  • Configuration and installation of SourceFire ASA

    Hello team,

    Recently, we have installed the SourceFire ASA-based software but its not in production, but now we intend to get SourceFire ASA production for the management of traffic and URL filtering. Right now, we have the FireSight of installation management system and uploaded image of SFR to ASA. Now ASA will exercise traffic of internet entry/exit point to our network. I have some doubts as follows:

    (1) ASA I see sfr module is in place, but what happens if I console module sfr this will affect my normal Internet traffic while I'm in the console of sfr.

    (2) are there models of basic configuration for the url filtering to make the job easier.

    (3) what are the control list to cross check before get sfr inline module in production.

    Thanks in advance for your help.

    Thank you - Jadesh

    Redirect us traffic to the fire power module using the modular policy framework for something like this:

     policy-map global_policy class class-default sfr fail-open service-policy global_policy global

    Generally, what you do on the console of sfr module do not affect the parent ASA. Until you have the policy to redirect traffic nothing will pass or affect by the module of sfr. As long as you have the 'rescue' the sfr descending module or the reset does not affect production ASA traffic.

    Of course once you run traffic through it and start applying policy, you have the option to block or otherwise affect this traffic.

    Beyond the user and Admin guides, you can take a glance series Lab Minutes that was done recently. They do a good job of walking your through basic tasks.

  • Using Zyxel wireless network configuration

    Using Panel to have Windows configure my system to use a wireless connection to internet via Zyxel USB. Using Windows options, network, Network Setup and configuration of wireless network connection me don't upset none the case. I understand there is a way that Windows will automatically connect. I need to update my Windows? I would like assistance. Bill

    Thanks for the information.

    No, you don't need an update.

    I do not understand your answer to no. 5, in particular "the material was not recognized by Windows, it requires a manual boot without Windows manages the connection of the device to the router."

    In Windows, there are basically two ways that a wireless adapter can be controlled.  Windows can control the unit by using a feature called 'Wireless Zero Configuration' or a utility provided by the manufacturer of the card.  As a general rule, you want one or the other - not both active at the same time.

    If the icon you are referencing is a 'Z' in a box (http://tinyurl.com/cjn3mje), then the Zyxel utility is in charge.   Which is perfectly OK (and probably provides more features than Windows WZC), but I'm not familiar with the details of using the Zyxel utility.  If you identify the model of your adapter, I can see if I can find his online user manual, and explain the steps you need to take

    If you use the Zyxel or Windows WZC utility, you must take the basic steps are the same:

    1. search for available wireless networks.
    2. identify your network in the list that is displayed (this is your SSID or 'Network name')
    3. click on "sign in".
    4. Enter the encryption password when you are prompted.

    Did you do the above?  That's happened?

    Additional information:

    Windows WZC automatically saves the connection (SSID and password) information once you connect successfully.  I don't know if the Zyxel utility done automatically or if you explicitly save a 'profile' with the data.

    Any utility that you use, you must know the SSID of your router and the password for the encryption.  Verizon technology that installed your router should provide you with this information.  It can also be written on a label on the bottom of the router.

    If you do not have - or lost - this information, you can find it by connecting to the router.  Preferably, you should do this using an Ethernet cable - assuming you can get your computer back close enough to the router.  You will need to know the name of user and password to connect to the router.  Again, Verizon technology would have to provide this information for you.

    As far as I can determine '20.10.7' is the revision number of the firmware of your router.  I believe - but am not sure - that the user guide is here--> http://www.actiontec.com/support/doc_files/MI424WR_Rev._E&F_User_Manual_20.10.7_v1_GPL.pdf

  • BlackBerry smartphone how to configure and use e-mail without BES

    Hello

    I'm trying to figure How to configure and use e-mail without using a BES.

    I checked with the local telephone company. And the number is not ascociated with any service of BES.

    The entry of services show no indication in this sense.

    In addition, the configuration of SIM card show that everything is disabled. This means that the phone is unlocked. At least that is my understanding.

    However, even after a wipe, the BB device does not set up an e-mail account, as described in the manual. He keeps asking for a BES activation first.

    What will do that disappears?

    And to allow the configuration of the "spam"?

    Just develop the right answer given by JSanders, you can always access your email accounts and social networks (facebook, twitter, google +, etc) on your phone, you will just have no notifications PUSHED to your phone.  You can access the internet on your phone in order to access these accounts, but it should go to them.  With BlackBerry Internet Service activated on your phone account, RIM will push these notifications of new emails, facebook messages, new tweets etc. for your phone.  That's what you'll be missing out on without active BIS.

    I wanted to just make sure that there is no likelihood of confusion.

  • Configure the public traffic network IP inside the internal network itself and not to the external network

    A server is now accessible from external network access using the IP and port in browser below http
    http://x.x.x.x:8080

    For the same, we have configured (static NAT) port forwarding in cisco security 1905.

    The application is also accessible via IP and the internal network port internal (ie. http://y.y.y.y:8080)

    Is there a way I can configure my 1905 Cisco as well as internal network (ie. machine B) I can access the application using the IP and the public port and not with the IP address internal? From now on, I'm not able to do the same.

    The current configurations are as follows:
    access-list 1 permit y.y.y.0 0.0.0.255
    IP nat inside source list 1 interface GigabitEthernet0/0 overload
    IP nat inside source tcp static y.y.y.y 8080 interface GigabitEthernet0/0 8080

    Hello

    You can try Domainless Nat.

    no nat ip within the source list 1 interface GigabitEthernet0/0 overload
    no nat inside source tcp ip static y.y.y.y 8080 interface GigabitEthernet0/0 8080

    int gig0/0
    no nat inside ip
    activate nat IP

    int gig0/1
    no nat inside ip
    activate nat IP

    IP nat source list 1 interface GigabitEthernet0/0 overload
    interface IP nat source tcp static y.y.y.y 8080 GigabitEthernet0/0 8080

    RES

    Paul

  • I can't do the network wireless hp 7500 to connect. I use wep-64 and shared.

    I can't network hp Officejet 7500 wireless to connect. I use wep-64 and shared.

    I have 7 systems properly using this configuration. 2 printers, 1 office, 1 router and 3 laptops).

    Well first of all, given that the printer is on a network, you need not to share.  All computers can simply install a network printer.

  • If you use network storage, configure ASM disks with external redundancy groups

    Hi Experts,

    If you use network storage, configure ASM disks with external redundancy groups. Don't use groups of Oracle ASM failure. Oracle failure groups consume cycles additional CPU and can run in unpredictable ways after suffering from a disk failure. When you use external redundancy, disk failure are transparent to the database and do consume no additional database CPU cycle, because it is discharged on storage processors.

    This does not mean

    • RAID 1 + 0 for diskgroup + REDO1
    • RAID 1 + 0 for diskgroup + REDO2
    • RAID 5 for diskgroup + DATA
    • RAID 5 for diskgroup + FRA

    Is this one suggested, the recommended best practices for oracle on VMWARE?


    Thank you and best regards,

    IVW


    Hello

    You can check the storage analysis as well...

    http://www.Dell.com/downloads/global/solutions/tradeoffs_RAID5_RAID10.PDF

    discussion of the Oracle

    https://asktom.Oracle.com/pls/asktom/f?p=100:11:P11_QUESTION_ID:359617936136

  • Old lock to activate ipad asking for Apple ID and password used to configure icloud, which is forgotten. Help?

    My older ipad bouchoirs activation requires Apple ID and password used to configure icloud. I think I know the ID because she tips ***@outlook.com, but not the old password. Help?

    Try https://iforgot.apple.com

    or

    Contact Apple for the Apple ID account security support

    https://support.Apple.com/en-us/HT204169

Maybe you are looking for