Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

CONNECTION TRACKING ON PIX

Hi.

How can i implement connection tracking acl on pix firewall?

Like cisco ios "access-list permit ip any any gt 1024 established".

Thanks.

12 REPLIES
New Member

Re: CONNECTION TRACKING ON PIX

The PIX does this much better than a router and you do not even need an ACL entry. Make sure you are logging the following syslog messages:

302013 - Built TCP connection

302014 - Teardown TCP connection

302015 - Built UDP connection

302016 - Teardown UDP connection

For details,

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/syslog/pixemsgs.htm

I wrote a perl script that is capable of quickly summarizing information gathered by these messages. I could send it to you if you like.

Kevin

New Member

Re: CONNECTION TRACKING ON PIX

I would like a copy of the script, please! Can you post it here? Thanks!

New Member

Re: CONNECTION TRACKING ON PIX

The script did not transfer well into the message box. I can email to you if you like?

Kevin

New Member

Re: CONNECTION TRACKING ON PIX

Hi Kevin,

would you please send me the script as well. thanks

nowcheckit@yahoo.com

New Member

Re: CONNECTION TRACKING ON PIX

Hi Kevin,

I'd love a copy of the script.

Appreciate it.

blackwoj@stjosephs_marshfield.org

New Member

Re: CONNECTION TRACKING ON PIX

Ok thanks, send me at

odoresemprevivo@hotmail.com

New Member

Re: CONNECTION TRACKING ON PIX

And i cannot implenet nothing to do connection tracking???

New Member

Re: CONNECTION TRACKING ON PIX

Kevin, could you also send me the script! i have beenlooking for something like that (didn't want to reinvent the wheel)

jfountain@rbinc.com

thanks!

New Member

Re: CONNECTION TRACKING ON PIX

Kevin, I'd love a copy of the script as well. matthew.richard@cocc.com.

If anyone is interested I have also written a perl script that shows all unusual messages as well as summaries of all denied packets. I have a version for the Pix 6.2 log files and one for IOS 12.x log files. Not sure if it is the same as Kevin's but I would be happy to share on request.

New Member

Re: CONNECTION TRACKING ON PIX

Kevin, could you send the script to me @ jfanter@stlcc.edu. Thanks

Jon F.

New Member

Re: CONNECTION TRACKING ON PIX

Kevin,

pls also send me the script and instructions:

gomesrichard@yahoo.com

thanks

richard

New Member

Re: CONNECTION TRACKING ON PIX

Kevin could I get a copy of that script e-mailed to me also..

robert.mcclain@lendersservice.com

Thanks

289
Views
0
Helpful
12
Replies