<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Accesslist on pix 525 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/accesslist-on-pix-525/m-p/255178#M566672</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It handles subnets fine but you have to use that syntax.  Instead of "host subnet" you need "subnet subnet-mask".  And from what you wrote about the purpose, I think you need to reverse the source/dest, assuming the ACL gets applied to the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_grp permit tcp theirsubnet subnet-mask gt 1023 host my-email-server eq smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;- Marty&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Apr 2004 17:18:56 GMT</pubDate>
    <dc:creator>MARTY ADKINS</dc:creator>
    <dc:date>2004-04-13T17:18:56Z</dc:date>
    <item>
      <title>Accesslist on pix 525</title>
      <link>https://community.cisco.com/t5/network-security/accesslist-on-pix-525/m-p/255176#M566663</link>
      <description>&lt;P&gt;I only want IP addresses on a specific subnet to be able tos end smtp traffic to my email server. I have tried the following access-lists but cannot get traffic to pass. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_grp permit tcp host myipaddress host theirsubnet eq smtp and I reversed the order of the addresses. I am wondering if the access-list command does not recognize entire subnets?  example: 209.165.201.0  ? &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/accesslist-on-pix-525/m-p/255176#M566663</guid>
      <dc:creator>shawn.s</dc:creator>
      <dc:date>2020-02-21T07:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Accesslist on pix 525</title>
      <link>https://community.cisco.com/t5/network-security/accesslist-on-pix-525/m-p/255177#M566668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe I wasn't clear enough.. I just want to create an access list that only allows hosts on a specified subnet to pass SMTP traffic to my email server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2004 12:03:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/accesslist-on-pix-525/m-p/255177#M566668</guid>
      <dc:creator>shawn.s</dc:creator>
      <dc:date>2004-04-13T12:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Accesslist on pix 525</title>
      <link>https://community.cisco.com/t5/network-security/accesslist-on-pix-525/m-p/255178#M566672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It handles subnets fine but you have to use that syntax.  Instead of "host subnet" you need "subnet subnet-mask".  And from what you wrote about the purpose, I think you need to reverse the source/dest, assuming the ACL gets applied to the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_grp permit tcp theirsubnet subnet-mask gt 1023 host my-email-server eq smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;- Marty&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2004 17:18:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/accesslist-on-pix-525/m-p/255178#M566672</guid>
      <dc:creator>MARTY ADKINS</dc:creator>
      <dc:date>2004-04-13T17:18:56Z</dc:date>
    </item>
  </channel>
</rss>

