<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall/m-p/665016#M1010318</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for quick reply.&lt;/P&gt;&lt;P&gt;However i want to know the meaning of following commands&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp host 10.25.25.16 host 203.45.18.1 eq domain&lt;/P&gt;&lt;P&gt;failover ip address state x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Mar 2007 13:15:37 GMT</pubDate>
    <dc:creator>nileshKahale</dc:creator>
    <dc:date>2007-03-15T13:15:37Z</dc:date>
    <item>
      <title>Firewall</title>
      <link>https://community.cisco.com/t5/network-security/firewall/m-p/665014#M1010309</link>
      <description>&lt;P&gt;Hi All ,&lt;/P&gt;&lt;P&gt;I am very new to Firewall. I have Cisco PIX 515E , I want to know regarding configuration of 515E &amp;amp; also want to know what happens with command fixup protocol , failover ip address outside,failover ip address state &amp;amp; how to use access list in Firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:46:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall/m-p/665014#M1010309</guid>
      <dc:creator>nileshKahale</dc:creator>
      <dc:date>2019-03-11T09:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall</title>
      <link>https://community.cisco.com/t5/network-security/firewall/m-p/665015#M1010314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Big subject &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) fixup protocol. Generally the pix looks at layer 3 (IP addresses) and layer 4 (port numbers). However for some applications it can look at the layer 7 information ie. it understands certain commands etc, used by the application. The applications it can do this for are defined by the fixup protocol lines. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) failover  - this is used when you have two firewalls in a pair. One is generally active and the other is in failover mode and will assume the active role if the primary firewall fails. Note that with v7.0 of the pix software you can run both in active mode if you want on a per context basis. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) access-lists are used to control the traffic allowed through the firewall, either from inside to outside or outside to inside, or outside to DMZ etc...&lt;/P&gt;&lt;P&gt;By default traffic is allowed to flow from a higher security interface to a lower security interface without an access-list eg inside to outside. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is a link to the pix firewall configuration docs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_installation_and_configuration_guides_list.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_installation_and_configuration_guides_list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 12:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall/m-p/665015#M1010314</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-15T12:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall</title>
      <link>https://community.cisco.com/t5/network-security/firewall/m-p/665016#M1010318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for quick reply.&lt;/P&gt;&lt;P&gt;However i want to know the meaning of following commands&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp host 10.25.25.16 host 203.45.18.1 eq domain&lt;/P&gt;&lt;P&gt;failover ip address state x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 13:15:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall/m-p/665016#M1010318</guid>
      <dc:creator>nileshKahale</dc:creator>
      <dc:date>2007-03-15T13:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall</title>
      <link>https://community.cisco.com/t5/network-security/firewall/m-p/665017#M1010324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list acl_in permit udp host 10.25.25.16 host 203.45.18.1 eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is allowing udp 53 (dns) traffic from 10.25.25.16 to 203.45.18.1, as long as acl_in is applied to an interface with something like "access-group acl_in in interface outside".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 13:21:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall/m-p/665017#M1010324</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-15T13:21:40Z</dc:date>
    </item>
  </channel>
</rss>

