<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 501 access-list deny not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753271#M1006953</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list joe deny tcp host 12.164.17.130 host 63.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq ftp &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq ftp &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx gt 60000 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx gt 60000 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1953 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx range 65438 65441 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1954 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1953 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1954 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx gt 60000 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq ftp &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq pcanywhere-data &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 5632 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq ftp &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq www &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq https &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1953 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1954 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1953 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1954 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Apr 2007 18:35:25 GMT</pubDate>
    <dc:creator>r.mazzella</dc:creator>
    <dc:date>2007-04-17T18:35:25Z</dc:date>
    <item>
      <title>PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753263#M1006943</link>
      <description>&lt;P&gt;There is someone trying to get access to my FTP server causing slowdowns and event log errors.  I have added his IP to my access list deny to that server and he is still able to access the server.  What did I do wrong if anything?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list joe deny tcp host 12.164.17.130 host 63.xxx.xxx.xxx&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753263#M1006943</guid>
      <dc:creator>r.mazzella</dc:creator>
      <dc:date>2019-03-11T10:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753264#M1006944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the acl applied or is there a permit before the deny?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:22:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753264#M1006944</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-04-17T18:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753265#M1006945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A couple of questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the access list applied to the outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a permit statement further up in the access list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the counters increasing on the line?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753265#M1006945</guid>
      <dc:creator>mark.hodge</dc:creator>
      <dc:date>2007-04-17T18:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753266#M1006946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to apply this access list to an interface (most likely the outside in your case)using the access-group command.  Here is an example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group joe in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:23:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753266#M1006946</guid>
      <dc:creator>jwalker</dc:creator>
      <dc:date>2007-04-17T18:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753267#M1006949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the acl is aplied and there is a permit after the deny.  I tried both way and the little S.O.B   is still getting access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:25:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753267#M1006949</guid>
      <dc:creator>r.mazzella</dc:creator>
      <dc:date>2007-04-17T18:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753268#M1006950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Either that is not the correct source address or something else is wrong, post up the whole acl.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753268#M1006950</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-04-17T18:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753269#M1006951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that is exactly what I have in already&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753269#M1006951</guid>
      <dc:creator>r.mazzella</dc:creator>
      <dc:date>2007-04-17T18:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753270#M1006952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can verify you have the correct "attacking IP" using the following method..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  Create an access list to look for traffic to your FTP server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cap1 extended permit tcp any host 63.1.1.1 eq ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.  Create a capture to look for traffic using your access list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture cap1 access-list cap1 interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. View capture &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show capure cap1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:33:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753270#M1006952</guid>
      <dc:creator>jwalker</dc:creator>
      <dc:date>2007-04-17T18:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753271#M1006953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list joe deny tcp host 12.164.17.130 host 63.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq ftp &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq ftp &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx gt 60000 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx gt 60000 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1953 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx range 65438 65441 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1954 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1953 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1954 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx gt 60000 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq ftp &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq pcanywhere-data &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 5632 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq ftp &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq www &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq https &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1953 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1954 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1953 &lt;/P&gt;&lt;P&gt;access-list joe permit tcp any host 63.xxx.xxx.xxx eq 1954 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753271#M1006953</guid>
      <dc:creator>r.mazzella</dc:creator>
      <dc:date>2007-04-17T18:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753272#M1006955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it comes up in my ftp logfile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753272#M1006955</guid>
      <dc:creator>r.mazzella</dc:creator>
      <dc:date>2007-04-17T18:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753273#M1006957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;never done a capture before.  I would need assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:38:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753273#M1006957</guid>
      <dc:creator>r.mazzella</dc:creator>
      <dc:date>2007-04-17T18:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753274#M1006960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do a show access-list joe. Do you have any hits on your deny line? If not then you have the wrong source address or this is not the source of your problem. Is that the entire acl?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 18:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753274#M1006960</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-04-17T18:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753275#M1006961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess it is possible that the attacker already has an open connection, and therfore the access list only gets checked on setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;run "sh conn" and "sh xlate" and check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could run "clear xlate" but this would cause an interupt for all users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 19:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753275#M1006961</guid>
      <dc:creator>mark.hodge</dc:creator>
      <dc:date>2007-04-17T19:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 access-list deny not working</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753276#M1006962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well try this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"shun 12.164.17.130" remember shun command cannot be saved therefore they will not be there after a reload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;very rarely on 6.x code (501s only run 6.X and down) i've seen commands that just do take effect ... sometimes you have to take it out and reapply it ... try that ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2007 19:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-access-list-deny-not-working/m-p/753276#M1006962</guid>
      <dc:creator>bahoosh</dc:creator>
      <dc:date>2007-04-18T19:10:31Z</dc:date>
    </item>
  </channel>
</rss>

