<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX ALIAS AND ACCESS-LIST in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-alias-and-access-list/m-p/44253#M721253</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list check is the first thing to be performed and must permit the packet as it arrives at the pix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Aug 2002 05:01:18 GMT</pubDate>
    <dc:creator>pgolding</dc:creator>
    <dc:date>2002-08-15T05:01:18Z</dc:date>
    <item>
      <title>PIX ALIAS AND ACCESS-LIST</title>
      <link>https://community.cisco.com/t5/network-security/pix-alias-and-access-list/m-p/44252#M721250</link>
      <description>&lt;P&gt;PIX Current setup:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside :- 10.32.0.0 /16&lt;/P&gt;&lt;P&gt;DMZ :- 10.112.3.0 /24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;alias (inside) 54.10.10.62 10.112.3.62 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp host 10.32.0.242 host 54.10.10.62 eq ftp &lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp host 10.32.0.242 host 10.112.3.62 eq ftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which entry in the access-list will be used..? Will the access-list get checked before the dnat function of the alias or after..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:12:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-alias-and-access-list/m-p/44252#M721250</guid>
      <dc:creator>v.kalingara</dc:creator>
      <dc:date>2020-02-21T06:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: PIX ALIAS AND ACCESS-LIST</title>
      <link>https://community.cisco.com/t5/network-security/pix-alias-and-access-list/m-p/44253#M721253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list check is the first thing to be performed and must permit the packet as it arrives at the pix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2002 05:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-alias-and-access-list/m-p/44253#M721253</guid>
      <dc:creator>pgolding</dc:creator>
      <dc:date>2002-08-15T05:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX ALIAS AND ACCESS-LIST</title>
      <link>https://community.cisco.com/t5/network-security/pix-alias-and-access-list/m-p/44254#M721257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list check is the first thing to be performed and must permit the packet as it arrives at the pix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2002 05:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-alias-and-access-list/m-p/44254#M721257</guid>
      <dc:creator>pgolding</dc:creator>
      <dc:date>2002-08-15T05:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: PIX ALIAS AND ACCESS-LIST</title>
      <link>https://community.cisco.com/t5/network-security/pix-alias-and-access-list/m-p/44255#M721262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So is the answer both ACLs need to be applied or just the first one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason I ask is I've been told that the "foreign address" (the second address in the 'alias' command) is not reachable from the interface it is applied to. But if this is not true, then theoretically traffic could arrive on the inside interface destined for either address and one would be d-NATed and the other wouldn't, right? And then we'd have to filter for both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2002 00:21:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-alias-and-access-list/m-p/44255#M721262</guid>
      <dc:creator>mkato</dc:creator>
      <dc:date>2002-08-22T00:21:09Z</dc:date>
    </item>
  </channel>
</rss>

