cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
725
Views
0
Helpful
2
Replies

Possible Crypto Overlap and NAT ACL open to Subnet vs. Host

pdvcisco
Level 1
Level 1

Hi,

For a PIX 515E 6.3(5)

I have the following ACLS:

Crypto ACL List

access-list ipsectraffic permit ip host 192.168.7.221 object-group pdvcorp-backup3-to-db1-datacenter
access-list ipsectraffic permit ip host 192.168.7.222 object-group pdvcorp-backup3-to-db1-datacenter
access-list ipsectraffic permit ip object-group corphosts-datacenter 192.168.10.0 255.255.255.0
access-list ipsectraffic permit ip object-group productionhosts-datacenter object-group access-productionhosts-datacenter

In the above Crypto ACL list, hosts 192.168.7.221 and 192.168.7.222 are both also part of the object group 'productionhosts-datacenter' referenced in the same ACL list. What are the implications of having the same hosts referenced in the Crypto ACL, if any?

No NAT Access List

access-list nonat permit ip 192.168.7.0 255.255.255.0 192.168.10.0 255.255.255.0

In relation to the Crypto ACLs above, is there an issue (security wise or other) with opening the complete Subnet with a NoNAT ACL to save on the having to nail down each host.

Thanks,

Dan

1 Accepted Solution

Accepted Solutions

droeun141
Level 1
Level 1

It doesn't matter, you can use the same source with multiple destinations.  No issues either with the nonat.

View solution in original post

2 Replies 2

droeun141
Level 1
Level 1

It doesn't matter, you can use the same source with multiple destinations.  No issues either with the nonat.

As droeun141 said, you should be fine

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: