cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
882
Views
0
Helpful
12
Replies

CONNECTION TRACKING ON PIX

giuliano
Level 1
Level 1

Hi.

How can i implement connection tracking acl on pix firewall?

Like cisco ios "access-list permit ip any any gt 1024 established".

Thanks.

12 Replies 12

kevin-reynolds
Level 1
Level 1

The PIX does this much better than a router and you do not even need an ACL entry. Make sure you are logging the following syslog messages:

302013 - Built TCP connection

302014 - Teardown TCP connection

302015 - Built UDP connection

302016 - Teardown UDP connection

For details,

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/syslog/pixemsgs.htm

I wrote a perl script that is capable of quickly summarizing information gathered by these messages. I could send it to you if you like.

Kevin

I would like a copy of the script, please! Can you post it here? Thanks!

The script did not transfer well into the message box. I can email to you if you like?

Kevin

Hi Kevin,

would you please send me the script as well. thanks

nowcheckit@yahoo.com

Hi Kevin,

I'd love a copy of the script.

Appreciate it.

blackwoj@stjosephs_marshfield.org

Ok thanks, send me at

odoresemprevivo@hotmail.com

And i cannot implenet nothing to do connection tracking???

Kevin, could you also send me the script! i have beenlooking for something like that (didn't want to reinvent the wheel)

jfountain@rbinc.com

thanks!

Kevin, I'd love a copy of the script as well. matthew.richard@cocc.com.

If anyone is interested I have also written a perl script that shows all unusual messages as well as summaries of all denied packets. I have a version for the Pix 6.2 log files and one for IOS 12.x log files. Not sure if it is the same as Kevin's but I would be happy to share on request.

Kevin, could you send the script to me @ jfanter@stlcc.edu. Thanks

Jon F.

Kevin,

pls also send me the script and instructions:

gomesrichard@yahoo.com

thanks

richard

Kevin could I get a copy of that script e-mailed to me also..

robert.mcclain@lendersservice.com

Thanks

Review Cisco Networking products for a $25 gift card