Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

From Conduits to ACLs

I'm new to the PIX and trying to migrate our conduits to ACLs. (520 PIX Version 6.2(2))

So far I've written the "acl_in" and "acl_out" access-lists, but I have a few questions.

(I've ordered a book, but am hoping to get some questions answered sooner.)

1st, should the access list be written based on the source of the traffic? e.g. if there is a node that needs to initiate traffic to another node outside the firewall should the ACL be written accordingly?

2nd, if that same node needs to be both the source and destiniation of traffic, should there be 2 ACLs? One on the inside, one on the outside?

3rd, when I need to update an access-list do I need to remove it and re-add it to add to it?

Thanks!

~Matt

2 REPLIES
Gold

Re: From Conduits to ACLs

Hello Matt,

Please read the following document (PDF) by Bill Donaldson of GSEC, a very good explanation of converting from conduits to ACLs.

http://www.giac.org/practical/GSEC/Bill_Donaldson_GSEC.pdf

Hope this helps and let me know if you need further explanation.

- Jay

Silver

Re: From Conduits to ACLs

Hi Matt,

There has been an earlier thread about converting conduits to ACL at this forum. Might be helpfull for you to read this one (and the provided URL's within this thread)

See:

http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&CommCmd=MB?cmd=display_location&location=.ee9bdf4

Kind regards,

Leo

88
Views
0
Helpful
2
Replies
CreatePlease login to create content