Converting Firewall Policy from Cisco ASA ACL
hi,
i'm migrating a cisco asa ACL to a FGT.
just to confirm, i'll always need to create 2x FW policy: inbound and outbound rule for each single ACL?
an example would be below:
!! ASA:
access-list DMZ-IN extended permit tcp object SERVER-SUBNET 10.200.0.0 255.255.0.0
access-group DMZ-IN in interface dmz
!! FGT:
edit DMZ-IN 1
set srcintf "any"
set dstintf "port 1" !! DMZ interface
set srcaddr "SERVER-SUBNET"
set dstaddr "10.200.0.0_16-SUBNET"
set service "ALL_TCP"
set schedule "always"
set logtraffic enable
set status enable
set action accept
set nat disable
next
edit DMZ-IN 2 !! JUST CLONE REVERSE FW POLICY 1
set srcintf "port 1"
set dstintf "any"
set srcaddr "10.200.0.0_16-SUBNET"
set dstaddr "SERVER-SUBNET"
set service "ALL_TCP"
set schedule "always"
set logtraffic enable
set status enable
set action accept
set nat disable
next
