Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

conduit and access list

hi,

is it possible to apply both conduit and access list on the same time and if yes what command is overwiite the other.

thanks

5 REPLIES

Re: conduit and access list

Just use access-lists !

Re: conduit and access list

Hi,

Cisco has supersede conduit with access-list command. You can still use conduit, but access-list is highly recommended. Access-list will be processed first before conduit command.

Additionally, access-list is more flexible control of connections in either direction. It allows for filtering based upon source and destination addressing and ports and are applied individually to each interface allowing for much more granular and secure control of connections passing through the PIX

http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_field_notice09186a00801d3621.shtml

Rgds,

AK

Re: conduit and access list

In PIX software versions 5.0.1 and later, ACLs with access groups can be used instead of conduits. Conduits are still available, but the decision should be made whether to use conduits or ACLs. It is not advisable to combine ACLs and conduits on the same configuration. If both are configured, ACLs take preference over the conduits.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094aad.shtml#conduit

New Member

Re: conduit and access list

By "ACLs take preference" does that mean they get applied first then the conduits get applied or does that mean conduit rules will not be applied if there is an ACL configured on the interface?

Re: conduit and access list

It means that ACL is preferred filtering method than conduit. Access filtering will only use ACL rules, not conduit (ignored).

Cisco recommended to use only either ACL or conduit, not mixing them both.

Rgds,

AK

123
Views
0
Helpful
5
Replies