Apply Firewall Access Lists to a Host

This topic describes applying firewall access lists to a host.

This module provides an action that adds a host to a network object group defined on PIX/ASA firewalls. These object groups are referenced by access list commands.

To add a host to an access list:

  1. Define a network object group for use by Forescout eyeSight on the firewall. See Naming Forescout Object Groups and Sample Firewall Commands.
  2. Define an access-list statement that refers to the network object group.

    Access list restrictions apply to all endpoints in the network object group.

  3. Create a policy that uses the Cisco PIX/ASA Access-list Action to assign hosts to the network object group.
    • Hosts that satisfy policy conditions are added to the object group on the target firewall(s). Access list restrictions apply to these hosts.
    • When hosts no longer satisfy policy conditions, they are removed from the object group. Access list restrictions no longer apply to these hosts.