cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
577
Views
0
Helpful
3
Replies

PIX Multiple access-groups

ppauly
Level 1
Level 1

Can I have multiple access-groups (and multiple ACLs) protecting an interface on a PIX (ver 6.3(4)), for example:

access-group in-house-rules-acl in interface outside

access-group spam-drop-rules-acl in interface outside

If so, when a packet passes the first rule set, will it be evaluated by the second set of ACLs?

3 Replies 3

Jon Marshall
Hall of Fame
Hall of Fame

Peter

No you can't. You can only apply one acl per direction altho on 6.3 i believe that can only be inbound.

Why do you need 2 acls, just combine them into one.

Jon

Ease of administration.

You should try object-group and remark.

Regards,

jerry

Review Cisco Networking products for a $25 gift card