ASA_object-group

1、定义object-group
    object-group network xxx
    network-object host 117.136.10.179
 
2、定义ACL
    access-list out extended deny tcp object-group xxx interface outside eq 端口
 
3、在接口应用ACL
    access-group out in interface outside
 
效果:在ASA定义阻断外网部分IP访问本地资源,此策略定义好后如有再添加外网IP,直接添加network-object host  就可以了

你可能感兴趣的:(职场,休闲,asa)