<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX operation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-operation/m-p/1198873#M860926</link>
    <description>&lt;P&gt;I read the info ( see attachment )in Cisco book "Cisco ASA , PIX,FSWM Firewall handbook , 2nd Edition by David Hucaby" &lt;/P&gt;&lt;P&gt;that for outbound operation , xlate happens before ACL (2nd line in attachemnt ). Moreover ACL uses translated IP rather than its local ones.&lt;/P&gt;&lt;P&gt;I think it has to be :&lt;/P&gt;&lt;P&gt;Packet from Inside to Outside :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL --&amp;gt; Routing --&amp;gt; NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet from Outside to Inside :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL --&amp;gt; NAT --&amp;gt; Routing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct me if I'm wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:17:41 GMT</pubDate>
    <dc:creator>rajeshiyer</dc:creator>
    <dc:date>2019-03-11T15:17:41Z</dc:date>
    <item>
      <title>PIX operation</title>
      <link>https://community.cisco.com/t5/network-security/pix-operation/m-p/1198873#M860926</link>
      <description>&lt;P&gt;I read the info ( see attachment )in Cisco book "Cisco ASA , PIX,FSWM Firewall handbook , 2nd Edition by David Hucaby" &lt;/P&gt;&lt;P&gt;that for outbound operation , xlate happens before ACL (2nd line in attachemnt ). Moreover ACL uses translated IP rather than its local ones.&lt;/P&gt;&lt;P&gt;I think it has to be :&lt;/P&gt;&lt;P&gt;Packet from Inside to Outside :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL --&amp;gt; Routing --&amp;gt; NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet from Outside to Inside :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL --&amp;gt; NAT --&amp;gt; Routing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct me if I'm wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:17:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-operation/m-p/1198873#M860926</guid>
      <dc:creator>rajeshiyer</dc:creator>
      <dc:date>2019-03-11T15:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX operation</title>
      <link>https://community.cisco.com/t5/network-security/pix-operation/m-p/1198874#M860928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rajesh ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding in case on ACL or Nat comes in ASA is , if the traffic initiate from inside network &amp;amp; want's to communicate to outside server(Internet) which 1st thing need is to be permit by ACL . If ACL Permit's the traffic then only it will forward the traffic otherwise will drop . After completing its looking for Global IP which he will get from the NAT , then it will route the packet . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Case of Connection from outside to inside ,give you an example .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your web server which is located inside segment &amp;amp; source is a Host which reside behind the Outside segment(Internet) wants to access the server , then in this case the Host(Internet) attempt to connect to webserver(Inside) on public ip which he get it through Static NAT . Then ASA Check the ACL if permit then forward the Packet &amp;amp; After coming to Nat interface it will unwrap the packet &amp;amp; transfer the packet to its original Local Ip address .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it will useable for you .&lt;/P&gt;&lt;P&gt;Please rate it ......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ritesh Malviya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Apr 2009 17:49:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-operation/m-p/1198874#M860928</guid>
      <dc:creator>r.malviya</dc:creator>
      <dc:date>2009-04-13T17:49:21Z</dc:date>
    </item>
  </channel>
</rss>

