Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

does this allow or deny ?PIX-6.3(1)

Hi

I have these two lines int he config .Does this mean ip allowed or denied ?

access-list Outside permit ip any any

access-list Outside deny ip any any

  • Firewalling
1 REPLY
Bronze

Re: does this allow or deny ?PIX-6.3(1)

Hi there,

The ACL is read from the top of the config to the bottom of the config.

So, assuming that you have posted the lines in the order they are in within the config, andto answer your question: it would permit all IP traffic.

It would permit all IP traffic because the pix would search through the ACL and reach the permit line before it reaches the deny line. When it reaches a matching ACL statement, it stops looking.

So if the two lines were reversed, ie

access-list Outside deny ip any any

access-list Outside permit ip any any

The pix would match on the deny statement and consequently all IP traffic would be dropped.

I hope that helps you out a bit :) If it does, can you please rate the answer?

Brad

188
Views
5
Helpful
1
Replies
This widget could not be displayed.