diff --git a/configs/bova/bova-mdf-a8360-sw1.cfg b/configs/bova/bova-mdf-a8360-sw1.cfg index c00c199..0b0bf17 100755 --- a/configs/bova/bova-mdf-a8360-sw1.cfg +++ b/configs/bova/bova-mdf-a8360-sw1.cfg @@ -52,6 +52,12 @@ object-group ip address clearpass_servers 10 10.1.40.115 20 10.1.40.116 30 10.1.40.117 +object-group ip address day-enterprise-servers + 10 10.1.230.11 + 20 10.1.40.108 +object-group ip address dns-servers + 10 10.1.40.10 + 20 10.1.48.11 object-group ip address dom_cont 10 10.1.40.10 20 10.1.40.95 @@ -60,6 +66,9 @@ object-group ip address dom_cont 50 10.1.203.21 60 10.1.48.10 70 10.21.48.10 +object-group ip address ntp-servers + 10 10.1.40.154 + 20 10.1.48.103 object-group ip address sccm_servers 10 10.1.48.53 20 10.41.21.221 @@ -131,6 +140,16 @@ access-list ip Image-acl 195 permit tcp any clearpass_servers group clearpass_tcp_ports 200 comment ClearPass_TCP_PORTS_OUT 205 deny any any any +access-list ip hvac-acl + 10 permit any 10.41.230.0/255.255.255.224 day-enterprise-servers + 20 permit udp 10.41.230.0/255.255.255.224 dns-servers eq dns + 30 permit udp 10.41.230.0/255.255.255.224 ntp-servers eq ntp + 40 permit icmp 10.41.230.0/255.255.255.252 10.41.230.0/255.255.255.224 + 50 permit icmp 10.41.230.0/255.255.255.224 10.41.230.0/255.255.255.252 + 60 deny any any 10.0.0.0/255.0.0.0 + 70 deny any any 192.168.0.0/255.255.0.0 + 80 deny any any 172.16.0.0/255.240.0.0 + 90 permit tcp 10.41.230.0/255.255.255.224 any eq 587 log count access-list ip users-acl 10 deny any any 192.168.0.0/255.255.0.0 20 permit any any any