<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access-list question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595781#M559132</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, that makes sense. This line is showing as quoted when issuing show runningconfig command. This is on a pix 501, version 6.3.&lt;/P&gt;&lt;P&gt;Is it assinged to no interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Mar 2011 19:16:46 GMT</pubDate>
    <dc:creator>Dustin Barnett</dc:creator>
    <dc:date>2011-03-25T19:16:46Z</dc:date>
    <item>
      <title>Access-list question</title>
      <link>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595779#M559130</link>
      <description>&lt;P&gt;I was going through an old PIX firewall config, and correct me if I'm wrong, but doesn't the following open the firewall to anything?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_in permit ip any any&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595779#M559130</guid>
      <dc:creator>Dustin Barnett</dc:creator>
      <dc:date>2019-03-11T20:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Access-list question</title>
      <link>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595780#M559131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you apply it on an outside interface then the answer is 'yes'. it opens the firewall for anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you your query is resolved.Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 17:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595780#M559131</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-03-25T17:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Access-list question</title>
      <link>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595781#M559132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, that makes sense. This line is showing as quoted when issuing show runningconfig command. This is on a pix 501, version 6.3.&lt;/P&gt;&lt;P&gt;Is it assinged to no interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 19:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595781#M559132</guid>
      <dc:creator>Dustin Barnett</dc:creator>
      <dc:date>2011-03-25T19:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Access-list question</title>
      <link>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595782#M559133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:barnettd@nulaid.com"&gt;barnettd@nulaid.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, that makes sense. This line is showing as quoted when issuing show runningconfig command. This is on a pix 501, version 6.3.&lt;/P&gt;&lt;P&gt;Is it assinged to no interface?&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to look for an access-group command with the same access-list name eg. if your access-list was called outside_in then you need to look for a line in your config - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_in in &lt;INTERFACE&gt;&amp;nbsp;&amp;nbsp; &amp;lt;-- where interface is the actual interface it is applied to. &lt;/INTERFACE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It may well be applied to inside interface although traffic is allowed out by default. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bear in mind also that simply having this line does not permit all traffic if applied to the outside interface. You also need NAT translations for traffic to be allowed but you should still remove it if it is applied to the outside and replace it with a more restrictive access-list ie. only allow in what you need to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 21:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595782#M559133</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2011-03-25T21:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Access-list question</title>
      <link>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595783#M559134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the adivce. It looks like this access-list is applied to the inside interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 22:55:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-question/m-p/1595783#M559134</guid>
      <dc:creator>Dustin Barnett</dc:creator>
      <dc:date>2011-03-25T22:55:32Z</dc:date>
    </item>
  </channel>
</rss>

