Cisco ASA 5505 Transparent Firewall only allow specific IP access SSH

  1. Define some groups
    1. object-group network sysadmin
    2. network-object host <IP>
    3. exit
    4. object-group network webhost
    5. network-object host <IP>
  2. Build access-list
    1. access-list inside-out permit tcp object-group sysadmin object-group webhost eq ssh
    2. access-list inside-out deny tcp any object-group webhost eq ssh
    3. access-list inside-out extended permit ip any any
  3. Apply to interface
    1. access-group inside-out out int inside

Leave a Reply