<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX inspection question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-inspection-question/m-p/49434#M626547</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for your post. &lt;/P&gt;&lt;P&gt;Do you have access to a sample config that will allow me to terminate the tunnel on the outside interface and statefully inspect all packets?&lt;/P&gt;&lt;P&gt;Thank you again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Oct 2002 14:35:07 GMT</pubDate>
    <dc:creator>cmd1</dc:creator>
    <dc:date>2002-10-30T14:35:07Z</dc:date>
    <item>
      <title>PIX inspection question</title>
      <link>https://community.cisco.com/t5/network-security/pix-inspection-question/m-p/49432#M626478</link>
      <description>&lt;P&gt;I have been told the PIX isn&amp;#146;t able to do stateful inspection on packets before passing them to the internal interface when terminating an IPSec VPN. I have also heard the packets are decrypted first then statefully inspected before being handed to the internal interface.&lt;/P&gt;&lt;P&gt;Which is correct?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-inspection-question/m-p/49432#M626478</guid>
      <dc:creator>cmd1</dc:creator>
      <dc:date>2020-02-21T06:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: PIX inspection question</title>
      <link>https://community.cisco.com/t5/network-security/pix-inspection-question/m-p/49433#M626496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both the statements are true. It depends on where your tunnel is terminating. Normally when the tunnel terminates on the outside interface, packet is decrypted -&amp;gt; stateful inspection is done. If the tunnel is terminated on the internal interface using the sysopt ipsec pl-compatible command then stateful inspection of the decrypted packet is not done. That is why it is suggested to use the nat 0 command instead of the sysopt ipsec pl-compatible. Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2002 14:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-inspection-question/m-p/49433#M626496</guid>
      <dc:creator>mohammed.ibrahim</dc:creator>
      <dc:date>2002-10-30T14:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: PIX inspection question</title>
      <link>https://community.cisco.com/t5/network-security/pix-inspection-question/m-p/49434#M626547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for your post. &lt;/P&gt;&lt;P&gt;Do you have access to a sample config that will allow me to terminate the tunnel on the outside interface and statefully inspect all packets?&lt;/P&gt;&lt;P&gt;Thank you again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2002 14:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-inspection-question/m-p/49434#M626547</guid>
      <dc:creator>cmd1</dc:creator>
      <dc:date>2002-10-30T14:35:07Z</dc:date>
    </item>
  </channel>
</rss>

