does this allow or deny ?PIX-6.3(1)

Unanswered Question
Aug 10th, 2009
User Badges:

Hi


I have these two lines int he config .Does this mean ip allowed or denied ?




access-list Outside permit ip any any


access-list Outside deny ip any any


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
bmcginn Mon, 08/10/2009 - 17:43
User Badges:
  • Bronze, 100 points or more

Hi there,


The ACL is read from the top of the config to the bottom of the config.


So, assuming that you have posted the lines in the order they are in within the config, andto answer your question: it would permit all IP traffic.


It would permit all IP traffic because the pix would search through the ACL and reach the permit line before it reaches the deny line. When it reaches a matching ACL statement, it stops looking.


So if the two lines were reversed, ie


access-list Outside deny ip any any

access-list Outside permit ip any any


The pix would match on the deny statement and consequently all IP traffic would be dropped.


I hope that helps you out a bit :) If it does, can you please rate the answer?


Brad

Actions

This Discussion