Re: pix firewall ports

From: Derek Zoolander (turbo6@grandnational.com)
Date: 05/09/02


From: "Derek Zoolander" <turbo6@grandnational.com>
Date: Thu, 09 May 2002 13:29:23 GMT

Thanks, Michael. I didn't know about invisible rule once an access-list is
created. That certainly makes things easier. :)

"Michael Sherman" <m-sherman.spam@cox.net> wrote in message
news:qtnjduk9h3r4iiqfdiqa7kel3mpueuqbpf@4ax.com...
> With PIX - if no access-lists are in place it is wide open. Once you
> put in one access list there is an invisible explicit deny rule. So,
> all you would do is create and access-list allowing http and smpt and
> thats it...everything else will be blocked.
>
> On Thu, 09 May 2002 00:11:32 GMT, "Derek Zoolander"
> <turbo6@grandnational.com> wrote:
>
> >What is the easiest way to close all ports except 80 and 25 outgoing on a
> >Cisco Pix firewall? Is it through access-lists?
> >
>
>
>
> m-sherman-spam@cox.net
> --------------------------
> Remove the -spam for email



Relevant Pages

  • Re: Gre through PIX 515E
    ... stations and use the log option to have the pix log the denied packet to the ... Then see if the denied packet is the packet you expected to be ... I applied access-lists to permit only gre ...
    (comp.dcom.sys.cisco)
  • Re: Enable SSL for Outlook Web Access
    ... :I am looking to configure my PIX 506E to be able to hit my two IIS ... I still cannot get through via SSL. ... All the configurations I can think of require adustment of -existing- ... my mind involving -two- new access-lists. ...
    (comp.dcom.sys.cisco)
  • Re: PIX ACLs for Inside/outside Nat and Crypto - All the same?
    ... Spreadsheet that Creates all 440 lines for each of the ACLs just in case... ... You appear to be using PIX 7 ... so the Cisco Tech recommended that for each of the Four lists I have ... I don't know about PIX 7, but in PIX 6, the contents of access-lists ...
    (comp.dcom.sys.cisco)
  • Cisco PIX VPN access-lists
    ... I am having difficulty configuring the VPN access-lists on LAN to LAN ... IPSec tunnel between a Cisco PIX and a Juniper SSG 20. ...
    (comp.dcom.sys.cisco)
  • Re: PIX ACLs for Inside/outside Nat and Crypto - All the same?
    ... VPN worked out and they recommended that my Access lists for allowing NATed ... You appear to be using PIX 7 ... I don't know about PIX 7, but in PIX 6, the contents of access-lists ... If you have that same ACL being used ...
    (comp.dcom.sys.cisco)