Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

How to create a new Service in ASA-5540?

I need to set up an ACL to allow only VNC access (TCP-5900) and thought I'd be able to create a new service for that. However I'm only able to create a new service-group. I did that, and clicked on 'add a new protocol' which I did for TCP 5900. Then I apply that when creating the ACL, but it does not do anything.

Is there a way to create a new service? Or what is the way you create an ACL that allows only VPN - or any single TCP port number for that matter that is not in the pre-defined service list?

1 REPLY

Re: How to create a new Service in ASA-5540?

try:-

object-group service VNC-TCP tcp

port-object eq 5900

access-list <> extended permit tcp <> <> object-group VNC-TCP

HTH.

175
Views
0
Helpful
1
Replies