<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access-list in PIX 506E in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-list-in-pix-506e/m-p/491970#M528245</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JC,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Change the access-list to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in deny ip host 192.168.1.247 any&lt;/P&gt;&lt;P&gt;access-list inside_access_in permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You blocked all non-TCP with your initial config.  This would have blocked DNS and nothing much would have worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps - pls rate posts that help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Paresh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Jan 2006 09:54:22 GMT</pubDate>
    <dc:creator>pkhatri</dc:creator>
    <dc:date>2006-01-26T09:54:22Z</dc:date>
    <item>
      <title>Access-list in PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/access-list-in-pix-506e/m-p/491969#M528243</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to block a single IP in the LAN (inside network )to access to the Internet. The following is the configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in deny tcp host 192.168.1.247 any&lt;/P&gt;&lt;P&gt;access-list inside_access_in permit tcp any any&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But instead on one IP address the access-list has block the entire LAN to access the Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly advise what is wrong with the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JC&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:40:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-in-pix-506e/m-p/491969#M528243</guid>
      <dc:creator>jclim</dc:creator>
      <dc:date>2020-02-21T08:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Access-list in PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/access-list-in-pix-506e/m-p/491970#M528245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JC,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Change the access-list to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in deny ip host 192.168.1.247 any&lt;/P&gt;&lt;P&gt;access-list inside_access_in permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You blocked all non-TCP with your initial config.  This would have blocked DNS and nothing much would have worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps - pls rate posts that help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Paresh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2006 09:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-in-pix-506e/m-p/491970#M528245</guid>
      <dc:creator>pkhatri</dc:creator>
      <dc:date>2006-01-26T09:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Access-list in PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/access-list-in-pix-506e/m-p/491971#M528249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raresh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's working now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TQ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2006 10:21:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-in-pix-506e/m-p/491971#M528249</guid>
      <dc:creator>jclim</dc:creator>
      <dc:date>2006-01-26T10:21:32Z</dc:date>
    </item>
  </channel>
</rss>

