<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 525 6.3 command line changes in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798016#M1008087</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rich &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) You can delete and insert individual lines on pix v 6.3 so no need to remove the entire list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) You can set the new peer within the crypto map without having to reenter entire map. Be aware that if you set another peer it will keep the original one unless you do a &lt;/P&gt;&lt;P&gt;"no set peer xxxxxx" on the original peer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Yes you can add entries to object-groups. It should not affect existing connections. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Apr 2007 16:27:10 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-04-05T16:27:10Z</dc:date>
    <item>
      <title>PIX 525 6.3 command line changes</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798015#M1008085</link>
      <description>&lt;P&gt;A few questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When changing access-lists on a PIX from command line, can you change one line in the list, or do you have to remove the entire existing list and re-enter the changed list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a crypto map, say the peer changes and you need to make that change, can you change one line in the crypto map, or does the entire map need to be re-entered with this change?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also same question for object group?&lt;/P&gt;&lt;P&gt;Can you add one line?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And will this affect any existing connections if it were a port objexct group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:56:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798015#M1008085</guid>
      <dc:creator>richmorrow624</dc:creator>
      <dc:date>2019-03-11T09:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 6.3 command line changes</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798016#M1008087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rich &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) You can delete and insert individual lines on pix v 6.3 so no need to remove the entire list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) You can set the new peer within the crypto map without having to reenter entire map. Be aware that if you set another peer it will keep the original one unless you do a &lt;/P&gt;&lt;P&gt;"no set peer xxxxxx" on the original peer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Yes you can add entries to object-groups. It should not affect existing connections. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2007 16:27:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798016#M1008087</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-04-05T16:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 6.3 command line changes</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798017#M1008090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;after you change ipsec peers, be sure to do a "clear crypto ipsec sa" and for kicks, "clear isakmp sa"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2007 16:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798017#M1008090</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-04-05T16:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 6.3 command line changes</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798018#M1008091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I wanted to change the list shown below, to add an additional host, it will allow me to add a line to the access-list NO_NAT?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or remove a single line?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list NO_NAT permit ip host 10.1.1.1 host 12.13.14.215&lt;/P&gt;&lt;P&gt;access-list NO_NAT permit ip host 10.1.1.2 host 12.13.14.215&lt;/P&gt;&lt;P&gt;access-list NO_NAT permit ip host 10.1.1.3 host 12.13.14.215&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2007 17:31:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798018#M1008091</guid>
      <dc:creator>richmorrow624</dc:creator>
      <dc:date>2007-04-05T17:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 6.3 command line changes</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798019#M1008093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rich &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to remove or add line(s) to the access-list eg &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list NO_NAT permit ip host 10.1.1.4 host 12.13.14.215 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will add to existing access-list NO_NAT &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list NO_NAT permit ip host 10.1.1.3 host 12.13.14.215 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will remove that line. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH and thanks for the rating &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2007 18:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798019#M1008093</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-04-05T18:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 6.3 command line changes</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798020#M1008094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply, just  a couple more questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX525 that currently has 10 VPN tunnels configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;9 are showing a idle and the below is not even showing up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AM I correct in a ssuming that with this config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. The crypto map looks correct and will match the address allowing remote side traffic from the 10.79.8.0 subnet to access the 10.91.9.0 subnet via VPN tunnel?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. The 10.91.9.1 and 2 addresses are being NATed from the 10.100.100.1 and 10.200.100.1 addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2007 21:14:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-6-3-command-line-changes/m-p/798020#M1008094</guid>
      <dc:creator>richmorrow624</dc:creator>
      <dc:date>2007-04-05T21:14:16Z</dc:date>
    </item>
  </channel>
</rss>

