Access Control: ACLs & Object Groups

Cisco ASA Firewall EVE-NG — ASAv (CLI + ASDM)

مقصدObjectiveObjective

Object groups کے ساتھ extended ACLs بنائیں اور interfaces پر apply کریں تاکہ security levels کے درمیان traffic control ہو۔Object groups ke sath extended ACLs banao aur interfaces par apply karo taake security levels ke darmiyan traffic control ho.Build extended ACLs with object groups and apply them to interfaces to control traffic between security levels.

آسان مثالSimple AnalogySimple Analogy

ACL گارڈ کی لکھی ہوئی instruction list ہے: 'delivery trucks کو gate B سے آنے دو، gate C سے سب کو روکو۔' Object groups صرف nicknames ہیں — 50 IP addresses لکھنے کے بجائے آپ لکھتے ہیں 'finance team'۔ACL guard ki likhi hui instruction list hai: 'delivery trucks ko gate B se ane do, gate C se sab ko roko.' Object groups sirf nicknames hain — 50 IP addresses likhne ke bajaye aap likhte hain 'finance team'.An ACL is the guard's written instruction list: 'let delivery trucks enter through gate B, block everyone from gate C.' Object groups are just nicknames — instead of listing 50 IP addresses, you write 'the finance team'.

سیٹ اپLab SetupLab Setup

asa-02 والا ASAv: inside 10.1.1.0/24، dmz 172.16.1.0/24 (web server 172.16.1.10)، outside 203.0.113.0/24 کی طرف۔ Goal: دنیا صرف DMZ web server تک ports 80/443 پر پہنچے۔asa-02 wala ASAv: inside 10.1.1.0/24, dmz 172.16.1.0/24 (web server 172.16.1.10), outside 203.0.113.0/24 ki taraf. Goal: duniya sirf DMZ web server tak ports 80/443 par pahunche.ASAv from asa-02: inside 10.1.1.0/24, dmz 172.16.1.0/24 (web server 172.16.1.10), outside facing 203.0.113.0/24. Goal: allow the world to reach only the DMZ web server on ports 80/443.

اقداماتStepsSteps

Step 1

DMZ servers کے لیے network object group اور web ports 80/443 کے لیے TCP service object group بنائیں۔DMZ servers ke liye network object group aur web ports 80/443 ke liye TCP service object group banao.Create a network object group for DMZ servers and a TCP service object group for web ports 80 and 443.

object-group network DMZ_SERVERS
network-object host 172.16.1.10
exit
object-group service WEB_PORTS tcp
port-object eq www
port-object eq https
exit

Step 2

Extended ACL لکھیں: کہیں سے بھی DMZ servers group تک TCP permit کریں، صرف web ports group پر۔ باقی سب end والے implicit deny سے deny ہو جائے گا۔Extended ACL likho: kahin se bhi DMZ servers group tak TCP permit karo, sirf web ports group par. Baqi sab end wale implicit deny se deny ho jayega.Write the extended ACL: permit TCP from anywhere to the DMZ servers group, only on the web ports group. Everything else is denied by the implicit deny at the end.

access-list OUTSIDE_IN extended permit tcp any object-group DMZ_SERVERS object-group WEB_PORTS

Step 3

ACL کو outside interface پر inbound apply کریں۔ Direction matter کرتی ہے: 'in' کا مطلب internet سے ASA میں داخل ہونے والا traffic۔ACL ko outside interface par inbound apply karo. Direction matter karti hai: 'in' ka matlab internet se ASA mein dakhil hone wala traffic.Apply the ACL inbound on the outside interface. Direction matters: 'in' means traffic entering the ASA from the internet.

access-group OUTSIDE_IN in interface outside

Step 4

Inside users کو full outbound access دیں: inside LAN سے all IP permit کرنے والی ACL، inside interface پر inbound apply کریں۔Inside users ko full outbound access do: inside LAN se all IP permit karne wali ACL, inside interface par inbound apply karo.Give inside users full outbound access with an ACL permitting all IP from the inside LAN, applied inbound on the inside interface.

access-list INSIDE_OUT extended permit ip 10.1.1.0 255.255.255.0 any
access-group INSIDE_OUT in interface inside

Step 5

ACLs اور ان کے hit counts verify کریں۔ ہر line بتاتی ہے کتنے packets match ہوئے — permit line پر zero hits کا مطلب traffic ASA تک نہیں پہنچ رہا یا match نہیں ہو رہا۔ACLs aur unke hit counts verify karo. Har line batati hai kitne packets match hue — permit line par zero hits ka matlab traffic ASA tak nahi pahunch raha ya match nahi ho raha.Verify the ACLs and their hit counts. Each line shows how many packets matched — zero hits on the permit line means the traffic isn't reaching the ASA or isn't matching.

show access-list OUTSIDE_IN
show access-list INSIDE_OUT

🖱️ ASDM: Configuration > Firewall > Access Rules — same rules table کی صورت میں؛ ہر row پر hit counts نظر آتے ہیں۔ASDM: Configuration > Firewall > Access Rules — same rules table ki surat mein; har row par hit counts nazar aate hain.ASDM: Configuration > Firewall > Access Rules — the same rules shown as a table; hit counts visible per row.

Step 6

Configuration save کریں۔Configuration save karo.Save the configuration.

write memory

تصدیقVerifyVerify

`show access-list` میں دونوں ACLs incrementing hit counts کے ساتھ نظر آئیں، `show run access-group` میں دونوں inbound applied ہوں، اور DMZ web server outside سے صرف port 80 پر reachable ہو۔`show access-list` mein dono ACLs incrementing hit counts ke sath nazar aain, `show run access-group` mein dono inbound applied hon, aur DMZ web server outside se sirf port 80 par reachable ho.`show access-list` shows the two ACLs with incrementing hit counts, `show run access-group` shows both applied inbound, and the DMZ web server is reachable from outside on port 80 only.

show access-list
show run access-group
show run object-group

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ ACL configured ہے لیکن traffic پھر بھی deny ہو رہا ہے۔ACL configured hai lekin traffic phir bhi deny ho raha hai.The ACL is configured but traffic is still denied.

✅ Confirm کریں ACL واقعی applied ہے `show run access-group` سے — لکھی ہوئی ACL interface پر bind ہوئے بغیر کچھ نہیں کرتی۔ Line order بھی check کریں: ASA top-down evaluate کرتا ہے، پہلا match جیتتا ہے۔Confirm karo ACL waqai applied hai `show run access-group` se — likhi hui ACL interface par bind hue baghair kuch nahi karti. Line order bhi check karo: ASA top-down evaluate karta hai, pehla match jeet ta hai.Confirm the ACL is actually applied with `show run access-group` — a written ACL does nothing until bound to an interface in the right direction. Also check line order: ASA evaluates top-down, first match wins.

⚠️ Object group changes کا اثر نظر نہیں آ رہا۔Object group changes ka asar nazar nahi aa raha.Object group changes don't seem to take effect.

✅ Object-group edits اسے reference کرنے والی ہر ACL پر فوراً apply ہوتی ہیں — دوبارہ apply کی ضرورت نہیں۔ اگر traffic پھر بھی fail ہو تو connection table clear کریں (`clear conn`) تاکہ پرانی denied sessions نہ رہیں۔Object-group edits usay reference karne wali har ACL par foran apply hoti hain — dobara apply ki zaroorat nahi. Agar traffic phir bhi fail ho to connection table clear karo (`clear conn`) taake purani denied sessions na rahen.Object-group edits apply immediately to every ACL referencing them — no re-apply needed. If traffic still fails, clear the connection table (`clear conn`) so old denied sessions don't persist.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ ASA پر standard اور extended ACL میں کیا فرق ہے؟ASA par standard aur extended ACL mein kya farq hai?What is the difference between a standard and an extended ACL on the ASA?

Extended ACL source اور destination IP plus protocol اور ports پر filter کرتی ہے، اور interface پر direction (in/out) میں apply ہوتی ہے۔ Standard ACL صرف source IP match کرتی ہے اور ASA پر rarely use ہوتی ہے۔Extended ACL source aur destination IP plus protocol aur ports par filter karti hai, aur interface par direction (in/out) mein apply hoti hai. Standard ACL sirf source IP match karti hai aur ASA par rarely use hoti hai.An extended ACL filters on source and destination IP plus protocol and ports, and is applied to an interface in a direction (in/out). A standard ACL only matches source IP and is rarely used on ASA.

❓ Network اور service object groups کیا ہیں، اور ASA پر انہیں کیوں use کیا جاتا ہے؟Network aur service object groups kya hain, aur ASA par inhein kyun use kiya jata hai?What are network and service object groups, and why are they used on the ASA?

Network object groups میں IPs/subnets ہوتے ہیں، service object groups میں protocols اور ports۔ ایک ACL line سے کئی hosts یا services cover ہو جاتی ہیں، policy short اور readable رہتی ہے۔ دیکھنے کے لیے `show run object-group` use کریں۔Network object groups mein IPs/subnets hote hain, service object groups mein protocols aur ports. Ek ACL line se kayi hosts ya services cover ho jati hain, policy short aur readable rehti hai. Dekhne ke liye `show run object-group` use karo.Network object groups hold IPs/subnets, service object groups hold protocols and ports. They let one ACL line cover many hosts or services, keeping the policy short and readable. Use `show run object-group` to view them.