对象组的 ASA 访问列表

网络工程 思科-ASA acl
2022-02-27 02:51:18

我对ASA不太熟悉,有没有办法把这个ACL变成一个对象组并且更容易维护?

access-list VPN-ALLOCATIONS extended permit esp 172.16.1.128 255.255.255.252 172.16.32.128 255.255.255.252
access-list VPN-ALLOCATIONS extended permit esp 172.16.32.128 255.255.255.252 172.16.1.128 255.255.255.252
access-list VPN-ALLOCATIONS extended permit esp 172.16.1.128 255.255.255.252 172.16.2.128 255.255.255.252
access-list VPN-ALLOCATIONS extended permit esp 172.16.2.128 255.255.255.252 172.16.1.128 255.255.255.252
access-list VPN-ALLOCATIONS extended permit esp 172.16.1.128 255.255.255.252 172.16.10.128 255.255.255.252
access-list VPN-ALLOCATIONS extended permit esp 172.16.10.128 255.255.255.252 172.16.1.128 255.255.255.252
access-list VPN-ALLOCATIONS extended permit esp 172.16.1.128 255.255.255.252 172.16.33.128 255.255.255.252
access-list VPN-ALLOCATIONS extended permit esp 172.16.33.128 255.255.255.252 172.16.1.128 255.255.255.252
access-list VPN-ALLOCATIONS extended permit udp any any eq isakmp
access-list VPN-ALLOCATIONS extended permit icmp any any

这是我所做的尝试,但我觉得它可能超出了我的需要:

object-group network VPN-SITES
 network-object host 172.16.1.130
 network-object host 172.16.2.130
 network-object host 172.16.10.130
 network-object host 172.16.32.130
 network-object host 172.16.33.130
object-group protocol APPROVED-PROTO
 protocol-object esp
 protocol-object icmp
!
access-list TEST extended permit object-group APPROVED-PROTO object-group VPN-SITES object-group VPN-SITES
access-list TEST extended permit object-group APPROVED-PROTO host 172.16.1.130 object-group VPN-SITES
access-list TEST extended permit object-group APPROVED-PROTO object-group VPN-SITES host 172.16.1.130
access-list TEST extended permit udp host 172.16.1.130 eq isakmp object-group VPN-SITES eq isakmp
access-list TEST extended permit udp object-group VPN-SITES eq isakmp host 172.16.1.130 eq isakmp
1个回答

你确实有一个多余的部分:

access-list TEST extended permit object-group APPROVED-PROTO host 172.16.1.130 object-group VPN-SITES
access-list TEST extended permit object-group APPROVED-PROTO object-group VPN-SITES host 172.16.1.130

因为 172.16.1.130 是该对象组 (VPN-SITES) 的一部分,您在 ACL 的第一行的源和目标位置都在使用它,因此无需进一步允许该主机。

因此,您可以删除这 2 行。