Is it common to deny tcp traffic entirely on ones network and only allow specific ip addresses out to the internet depending on port (80, 443, etc.)? Here is an example:
access-list account_in permit tcp 10.1.1.117 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.44 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.144 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.100 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.112 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.51 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.84 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.146 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.87 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.110 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.117 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.44 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.144 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.100 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.51 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.84 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.146 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.87 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.110 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.100 255.255.255.255 any eq 1070
access-list account_in permit tcp 10.1.1.100 255.255.255.255 any eq 1070
access-list account_in permit tcp 10.1.1.146 255.255.255.255 any eq 8080
access-list tsi_in deny ip any any
access-group tsi_in in interface inside
access-group account_in in interface inside
This is just a small example of my config. This is a real monster. Any suggestions or examples would be fantastic. Thanks.
access-list account_in permit tcp 10.1.1.117 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.44 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.144 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.100 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.112 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.51 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.84 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.146 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.87 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.110 255.255.255.255 any eq 80
access-list account_in permit tcp 10.1.1.117 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.44 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.144 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.100 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.51 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.84 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.146 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.87 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.110 255.255.255.255 any eq 443
access-list account_in permit tcp 10.1.1.100 255.255.255.255 any eq 1070
access-list account_in permit tcp 10.1.1.100 255.255.255.255 any eq 1070
access-list account_in permit tcp 10.1.1.146 255.255.255.255 any eq 8080
access-list tsi_in deny ip any any
access-group tsi_in in interface inside
access-group account_in in interface inside
This is just a small example of my config. This is a real monster. Any suggestions or examples would be fantastic. Thanks.