cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1494
Views
0
Helpful
2
Replies

Reduce PIX ACL

echee
Level 1
Level 1

I found that there are only host objects and network objects in PIX. Therefore, if I have ten machines such as 10.1.0.1, 10.1.0.3, 10.1.0.5,...... 10.1.0.19 and each of them needs to access 100 subnets such as 10.0.1.0/24, 10.0.3.0/24, 10.0.5.0/24, ..... 10.0.199.0/24 with ten protocols such as smtp, snmp, pop3, telnet, ssh, ftp, http, https, dns, imap, do I have to make 10 x 100 x 10 = 10000 access-lists? For Checkpoint FW-1, if I group the ten machines into a group object and group the 100 subnets as another group object and group the 10 services as a group service, then I just need one rule for this. I've upgraded the software to 6.1 and installed the PIX Device Manager 1.1 and search thoroughly on CCO but can't find any example that can reduce the complexity of the ruleset, could anyone give me some hints on how to reduce the number of rules? Thanks.

2 Replies 2

mkaneko
Cisco Employee
Cisco Employee

The grouping feature is not yet available on the PIX

(as of 6.11). The feature is under plan for next release. Using this feature, user can group several categories such as host, service and etc.

Current solution for easy configuration is the use of CSPM.

elehman
Level 1
Level 1

Um, you sure this isn't you?? -> http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.ee73f78

Someone else asked the SAME exact question - and it was answered correctly.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card