Forum Discussion

Amr_Esmat_24704's avatar
Amr_Esmat_24704
Icon for Nimbostratus rankNimbostratus
Sep 07, 2018

should I add deny all policy at end of Advanced Resource Assignment

should I add deny at end of Advanced Resource Assignment to deny any access except the access specified in the access list, like below example I have entry that have specific access list then I added deny at end that will match on all entry because it doesn't have expression, by this the entry will only have access to IPs in access list any other IPs are denied or should I remove the deny rule as the default implicit is deny?, will the user have access to any without this explicit deny rule?

 

also if resource assign order doesn't matter, does this mean if the deny entry loaded first before the permit entry user will not be able to access any resources?

 

 

2 Replies

  • Yes, it is recommended to add such ACL!

     

    But the resource assign order doesn’t matter! The ACL order does!

     

  • ACL order matters. then inside ACL, entry order matters...

     

    Why 1000??? do you really need more than 1000 ACL?

     

    I don't know if there is a limit. you can try with 10000.

     

    but any time you create a new resource, don't forget to define an ACL order less than the deny all ACL.