<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX and ACL on inside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-and-acl-on-inside-interface/m-p/290917#M562828</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if the client is on inside and you are permitting ftp through your ACL, fixup should open up outbound datachannel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same for inside FTP server if you have ACL that says permit tcp eq 21, fixup should open inbound data channel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Aug 2004 01:44:25 GMT</pubDate>
    <dc:creator>nkhawaja</dc:creator>
    <dc:date>2004-08-27T01:44:25Z</dc:date>
    <item>
      <title>PIX and ACL on inside interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-acl-on-inside-interface/m-p/290916#M562826</link>
      <description>&lt;P&gt;Quick PIX question guys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Say you have the normal inside (Sec100) and outside (Sec0) interfaces.  You have an ACL on the outside interface that allows access to an internal mail server or whatever.  Now, you also want to restrict what outbound traffic the users on the inside interface can initiate outbound so you create an ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_in permit tcp &amp;lt;internal IPs&amp;gt; any eq www&lt;/P&gt;&lt;P&gt;access-list inside_in permit tcp &amp;lt;internal IPs&amp;gt; any eq https&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;access-list inside_in permit tcp &amp;lt;internal IPs&amp;gt; any eq ftp&lt;/P&gt;&lt;P&gt;access-list inside_in permit tcp &amp;lt;internal IPs&amp;gt; any eq ftp-data&lt;/P&gt;&lt;P&gt;access-list inside_in deny any any&lt;/P&gt;&lt;P&gt;access-group inside_in in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about passive FTP?  Even if you have the fixup protocol configured for 21 on the PIX, that doesn't do much for inbound passive FTP data connections from the internal users does it or will the PIX be smart enough to know to allow the client-initiated passive FTP data connections out to the Internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-acl-on-inside-interface/m-p/290916#M562826</guid>
      <dc:creator>jamey</dc:creator>
      <dc:date>2020-02-21T07:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and ACL on inside interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-acl-on-inside-interface/m-p/290917#M562828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if the client is on inside and you are permitting ftp through your ACL, fixup should open up outbound datachannel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same for inside FTP server if you have ACL that says permit tcp eq 21, fixup should open inbound data channel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Aug 2004 01:44:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-acl-on-inside-interface/m-p/290917#M562828</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-08-27T01:44:25Z</dc:date>
    </item>
  </channel>
</rss>

