<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Outbound Constraints in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-outbound-constraints/m-p/23314#M654948</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1)  you can still use outbound statements, but they are not recommended.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)  No, there is not "out" parameter.  Reason being, traffic coming "in" one interface has to go "out" another interface.  So, better to block the traffic coming in, than going out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case, you would apply an access-list inbound on the Inside interface.  It would have "deny" statements for hosts going from the inside to the DMZ servers you don't want them to reach, and then a "permit ip any any" at the end for everything else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the Output Interpreter tool on CCO will soon have a conduit/outbound -&amp;gt; ACL converter.  Stay tuned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Jun 2002 20:58:40 GMT</pubDate>
    <dc:creator>David White</dc:creator>
    <dc:date>2002-06-05T20:58:40Z</dc:date>
    <item>
      <title>PIX Outbound Constraints</title>
      <link>https://community.cisco.com/t5/network-security/pix-outbound-constraints/m-p/23313#M654947</link>
      <description>&lt;P&gt;I'm in the process of converting from conduits to ACL and need some clarification on constraining outbound traffic.  The situation is that inside zone hosts (highest security) are banned from certain DMZs (lower security).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been using outbound deny &amp;amp; apply to enforce these constraints.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Are these statements still current and recommended in an ACL environment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The access-group documentation/syntax uses an "in" parameter but has no mention of whether there is an "out" parameter.  Is there one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:05:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-outbound-constraints/m-p/23313#M654947</guid>
      <dc:creator>cyee</dc:creator>
      <dc:date>2020-02-21T06:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Outbound Constraints</title>
      <link>https://community.cisco.com/t5/network-security/pix-outbound-constraints/m-p/23314#M654948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1)  you can still use outbound statements, but they are not recommended.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)  No, there is not "out" parameter.  Reason being, traffic coming "in" one interface has to go "out" another interface.  So, better to block the traffic coming in, than going out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case, you would apply an access-list inbound on the Inside interface.  It would have "deny" statements for hosts going from the inside to the DMZ servers you don't want them to reach, and then a "permit ip any any" at the end for everything else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the Output Interpreter tool on CCO will soon have a conduit/outbound -&amp;gt; ACL converter.  Stay tuned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2002 20:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-outbound-constraints/m-p/23314#M654948</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2002-06-05T20:58:40Z</dc:date>
    </item>
  </channel>
</rss>

