[fw-wiz] PIX question



So, you have an internet-out ACL which ends with an any any on the
inside interface.
You have an internet-in ACL on the outside interface.
You have a DMZ2-in ACL on the dmz2 interface.

The inside interface is 100, dmz2 is 10 (as is dmz1) and the outside
interface is 0.

You have an smtp box on dmz2. You have rules in dmz2-in allowing the
smtp box to talk to boxes on the internal network. The smtp box can
NOT talk to anything on the internet - gets denied by dmz2-in ACL. Add
an any any rule for that host in dmz2-in and it works.

Question: Why would the inbound ACL on dmz2 prevent it from sending
traffic to the outside interface with a lower security setting? Does
an ACL applied to a dmz interface have an implied deny all - even for
lower security interfaces?
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Pix 515 VLAN NAT0 issues
    ... that ACL will be exempt from NAT. ... the packet at the time the PIX receives the packet. ... ACL applied to an inside interface would have the internal IPs as ... accepted as having a translation and satisfying the security policies. ...
    (comp.dcom.sys.cisco)
  • Re: PIX 525 and swapping interface definitions
    ... If the ACL is used in a crypto map or static or nat ... then the extra ACL line referencing the old interface ... access-lists were absolutely mutually exclusive by design, ...
    (comp.dcom.sys.cisco)
  • Re: Questions on "sysopt connection permit-ipsec"
    ... :interface enabled for IPSEC, say the outside interface: ... :even if the outside interface ACL does not explicitly allow for it. ... :access-list ipsectraffic permit tcp host 10.1.1.3 any ... When an IPSec packet is received and successfully decoded, ...
    (comp.dcom.sys.cisco)
  • Re: [fw-wiz] PIX question
    ... You have an internet-in ACL on the outside interface. ... NOT talk to anything on the internet - gets denied by dmz2-in ACL. ... traffic to the outside interface with a lower security setting? ...
    (Firewall-Wizards)
  • RE: [fw-wiz] PIX Config Problem
    ... All is correct with exception of ACL 100 destination ... host IP, should be the outside interface IP. ... I use the 501 w/ DSL config as well and use "interface" option in my ... I'm testing the new 6.3.1 code and have found the following in the ACL ...
    (Firewall-Wizards)