<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Convert static/conduit to access-list in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742195#M1009056</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the static remains the same , you need to add the following access-lists :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit tcp any host x.x.x.x eq ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit tcp any host x.x.x.x eq 81&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit tcp any host x.x.x.x eq 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit tcp any host 111.111.111.25 eq 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit udp any host 111.111.111.25 eq 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit tcp host 207.214.246.57 host 111.111.111.25 eq snmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-g out_acl in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note*:- x.x.x.x---&amp;gt;public ip of outside interface of firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see if this helps !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Mar 2007 00:07:29 GMT</pubDate>
    <dc:creator>abinjola</dc:creator>
    <dc:date>2007-03-28T00:07:29Z</dc:date>
    <item>
      <title>Convert static/conduit to access-list</title>
      <link>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742194#M1009054</link>
      <description>&lt;P&gt;I know I'm old school and I'm a crotchety old IT guy. Static and conduits worked fine for me and dagnabit, I want to keep things that way. Alas, I know that can't go on forever. So can someone help me convert a few commands to access-lists please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) static (inside,outside) tcp interface ftp 192.168.1.10 ftp netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;2) static (inside,outside) tcp interface 81 192.168.1.10 www netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the associated conduit commands&lt;/P&gt;&lt;P&gt;3) conduit permit tcp any eq ftp any&lt;/P&gt;&lt;P&gt;4) conduit permit tcp any eq 81 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5) static (inside,outside) 111.111.111.25 mail netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;conduit permit tcp host 111.111.111.25 eq smtp any &lt;/P&gt;&lt;P&gt;conduit permit udp host 111.111.111.25 eq 25 any &lt;/P&gt;&lt;P&gt;conduit permit udp host 111.111.111.25 eq snmp host 207.214.246.57 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much any and all that help. I really need to get out of my PIX 5.0 days. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742194#M1009054</guid>
      <dc:creator>iscs-mark</dc:creator>
      <dc:date>2019-03-11T09:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: Convert static/conduit to access-list</title>
      <link>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742195#M1009056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the static remains the same , you need to add the following access-lists :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit tcp any host x.x.x.x eq ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit tcp any host x.x.x.x eq 81&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit tcp any host x.x.x.x eq 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit tcp any host 111.111.111.25 eq 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit udp any host 111.111.111.25 eq 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l out_acl permit tcp host 207.214.246.57 host 111.111.111.25 eq snmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-g out_acl in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note*:- x.x.x.x---&amp;gt;public ip of outside interface of firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see if this helps !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 00:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742195#M1009056</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-28T00:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Convert static/conduit to access-list</title>
      <link>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742196#M1009058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "out_acl" is just a name right? It can be anything correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 16:04:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742196#M1009058</guid>
      <dc:creator>iscs-mark</dc:creator>
      <dc:date>2007-03-28T16:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Convert static/conduit to access-list</title>
      <link>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742197#M1009061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that's right.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 16:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742197#M1009061</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2007-03-28T16:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Convert static/conduit to access-list</title>
      <link>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742198#M1009063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, most appreciated. Now I can ditch my 506 and get a 5505!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 16:07:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742198#M1009063</guid>
      <dc:creator>iscs-mark</dc:creator>
      <dc:date>2007-03-28T16:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Convert static/conduit to access-list</title>
      <link>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742199#M1009065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also note that Cisco's Output Interpreter will automatically convert conduits/outbounds to ACLs for you.  Just upload your config (via SSL) and hit a button &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 17:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742199#M1009065</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2007-03-28T17:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Convert static/conduit to access-list</title>
      <link>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742200#M1009067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That won't be when I do a copy/paste then correct? That will be when I upload a config with a TFTP? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 17:52:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742200#M1009067</guid>
      <dc:creator>iscs-mark</dc:creator>
      <dc:date>2007-03-28T17:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: Convert static/conduit to access-list</title>
      <link>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742201#M1009069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can copy and paste your config into OI.  Or, you can save the config in a file (via TFTP or copying and pasting it to notepad) and then just upload the file.  Either way works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See OI here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://www.cisco.com/pcgi-bin/Support/OutputInterpreter/home.pl" target="_blank"&gt;https://www.cisco.com/pcgi-bin/Support/OutputInterpreter/home.pl&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 18:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742201#M1009069</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2007-03-28T18:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Convert static/conduit to access-list</title>
      <link>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742202#M1009072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that David. That's pretty cool! Makes my life easier.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 18:33:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-static-conduit-to-access-list/m-p/742202#M1009072</guid>
      <dc:creator>iscs-mark</dc:creator>
      <dc:date>2007-03-28T18:33:19Z</dc:date>
    </item>
  </channel>
</rss>

