cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
558
Views
0
Helpful
3
Replies

PIX Multiple access-groups

ppauly
Level 1
Level 1

Can I have multiple access-groups (and multiple ACLs) protecting an interface on a PIX (ver 6.3(4)), for example:

access-group in-house-rules-acl in interface outside

access-group spam-drop-rules-acl in interface outside

If so, when a packet passes the first rule set, will it be evaluated by the second set of ACLs?

3 Replies 3

Jon Marshall
Hall of Fame
Hall of Fame

Peter

No you can't. You can only apply one acl per direction altho on 6.3 i believe that can only be inbound.

Why do you need 2 acls, just combine them into one.

Jon

Ease of administration.

You should try object-group and remark.

Regards,

jerry

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: