cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
311
Views
4
Helpful
1
Replies

Enable/Disable remote access to inside of PIX

otnj2ee
Level 1
Level 1

For a remote PC (VPN Client) to access to the inside of the Pix firewall, I'll issue a CML:

http 10.10.10.0 255.255.255.0 inside

Now, I want to reverse the above command, i.e. to disable the Remote access to the inside of the Pix. What is the command to do so? And where can I find the online reference (doc) for it?

Thanks to help

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

Unless you have the "management-access inside" command configured, then no-one can access the inside interface from the outside anyway, so if you want to deny all access then remove the above command.

I'm not actually sure what you're asking here, if you simply want to remove the "http . .." command above just preface it with "no".

If you want to deny 10.10.10.0/24 HTTP access to the inside but allow everyone else, then that's a bit more difficult. Remember that in the PIX unless it's specified, it is denied by default, so you can simply add "http" commands for those networks you do want to have access, and if 10.10.10.0 is not listed it will be denied.

The management-access (and all other) command is described here:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/index.htm

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: