Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

conduits on PIX 515

I am about to convert this PIX to ACLs, I can do a show conduit and see that some of them have no hitcount, would it be safe to remove these before converting to ACLs?

  • Other Security Subjects
1 REPLY
New Member

Re: conduits on PIX 515

You probably have inherited this PIX from someone who has left your company and left no documentation. So before removing a conduit from config, check the conduit hosts src/dst/protocole and ensure it's useless. Dont forget some conduits may have not been requested since pix last reload or modification so hitcount has been resetted. Also you may have indication on PIX syslog's of the usage from this conduit.

Mixed ACL and conduit are not supported by the PIX.

There's a link that may help you for the convertion of conduit to ACL if you have CCO account:

https://www.cisco.com/cgi-bin/Support/OutputInterpreter/home.pl

Michael

118
Views
0
Helpful
1
Replies
This widget could not be displayed.