cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
227
Views
0
Helpful
2
Replies

From Conduits to ACLs

mschmidt
Level 1
Level 1

I'm new to the PIX and trying to migrate our conduits to ACLs. (520 PIX Version 6.2(2))

So far I've written the "acl_in" and "acl_out" access-lists, but I have a few questions.

(I've ordered a book, but am hoping to get some questions answered sooner.)

1st, should the access list be written based on the source of the traffic? e.g. if there is a node that needs to initiate traffic to another node outside the firewall should the ACL be written accordingly?

2nd, if that same node needs to be both the source and destiniation of traffic, should there be 2 ACLs? One on the inside, one on the outside?

3rd, when I need to update an access-list do I need to remove it and re-add it to add to it?

Thanks!

~Matt

2 Replies 2

jmia
Level 7
Level 7

Hello Matt,

Please read the following document (PDF) by Bill Donaldson of GSEC, a very good explanation of converting from conduits to ACLs.

http://www.giac.org/practical/GSEC/Bill_Donaldson_GSEC.pdf

Hope this helps and let me know if you need further explanation.

- Jay

l.mourits
Level 5
Level 5

Hi Matt,

There has been an earlier thread about converting conduits to ACL at this forum. Might be helpfull for you to read this one (and the provided URL's within this thread)

See:

http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&CommCmd=MB?cmd=display_location&location=.ee9bdf4

Kind regards,

Leo

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: