<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reduce PIX ACL in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reduce-pix-acl/m-p/27048#M724733</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Um, you sure this isn't you?? -&amp;gt; &lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.ee73f78" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.ee73f78&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Someone else asked the SAME exact question - and it was answered correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 10 Nov 2001 02:58:17 GMT</pubDate>
    <dc:creator>elehman</dc:creator>
    <dc:date>2001-11-10T02:58:17Z</dc:date>
    <item>
      <title>Reduce PIX ACL</title>
      <link>https://community.cisco.com/t5/network-security/reduce-pix-acl/m-p/27046#M724687</link>
      <description>&lt;P&gt;I found that there are only host objects and network objects in PIX.  Therefore, if I have ten machines such as 10.1.0.1, 10.1.0.3, 10.1.0.5,...... 10.1.0.19 and each of them needs to access 100 subnets such as 10.0.1.0/24, 10.0.3.0/24, 10.0.5.0/24, ..... 10.0.199.0/24 with ten protocols such as smtp, snmp, pop3, telnet, ssh, ftp, http, https, dns, imap, do I have to make 10 x 100 x 10 = 10000 access-lists?  For Checkpoint FW-1, if I group the ten machines into a group object and group the 100 subnets as another group object and group the 10 services as a group service, then I just need one rule for this.  I've upgraded the software to 6.1 and installed the PIX Device Manager 1.1 and search thoroughly on CCO but can't find any example that can reduce the complexity of the ruleset, could anyone give me some hints on how to reduce the number of rules?  Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:53:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reduce-pix-acl/m-p/27046#M724687</guid>
      <dc:creator>echee</dc:creator>
      <dc:date>2020-02-21T05:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce PIX ACL</title>
      <link>https://community.cisco.com/t5/network-security/reduce-pix-acl/m-p/27047#M724703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The grouping feature is not yet available on the PIX &lt;/P&gt;&lt;P&gt;(as of 6.11). The feature is under plan for next release.  Using this feature, user can group several categories such as host, service and etc. &lt;/P&gt;&lt;P&gt;Current solution for easy configuration is the use of CSPM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2001 22:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reduce-pix-acl/m-p/27047#M724703</guid>
      <dc:creator>mkaneko</dc:creator>
      <dc:date>2001-11-06T22:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce PIX ACL</title>
      <link>https://community.cisco.com/t5/network-security/reduce-pix-acl/m-p/27048#M724733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Um, you sure this isn't you?? -&amp;gt; &lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.ee73f78" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.ee73f78&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Someone else asked the SAME exact question - and it was answered correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Nov 2001 02:58:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reduce-pix-acl/m-p/27048#M724733</guid>
      <dc:creator>elehman</dc:creator>
      <dc:date>2001-11-10T02:58:17Z</dc:date>
    </item>
  </channel>
</rss>

