cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
367
Views
0
Helpful
1
Replies

conduits on PIX 515

m.jensen
Level 1
Level 1

I am about to convert this PIX to ACLs, I can do a show conduit and see that some of them have no hitcount, would it be safe to remove these before converting to ACLs?

1 Reply 1

mpalardy
Level 3
Level 3

You probably have inherited this PIX from someone who has left your company and left no documentation. So before removing a conduit from config, check the conduit hosts src/dst/protocole and ensure it's useless. Dont forget some conduits may have not been requested since pix last reload or modification so hitcount has been resetted. Also you may have indication on PIX syslog's of the usage from this conduit.

Mixed ACL and conduit are not supported by the PIX.

There's a link that may help you for the convertion of conduit to ACL if you have CCO account:

https://www.cisco.com/cgi-bin/Support/OutputInterpreter/home.pl

Michael

Review Cisco Networking products for a $25 gift card