We have a conduit on our test PIX allowing IP any from the DMZ to the internal network. I read this on Cisco's website regarding IP any: Note: Be careful when implementing these commands. If either the conduit permit ip any any or access-list 101 pe...