cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
361
Views
0
Helpful
2
Replies

Can PIX allow out of session packets?

jsluzewski
Level 1
Level 1

Will "conduit permit ip host 1.1.1.1 any" permit out of state packets to host 1.1.1.1?

In asymetric routing scenario with two independent PIXes, inside host 1.1.1.1 (assume it is a valid public address, no NAT) starts connection to a destination outside. Will the PIX that sees ONLY session's inbound traffic to 1.1.1.1 permit it based on the above conduit statement?

Thanks

Jarek

2 Replies 2

rais
Level 7
Level 7

No, PIX will not permit out of state packets in. The packets, for a given session, must exit and enter through the same pix.

HTH

Are you sure?

The conduit allows ANY IP traffic.

If not, how would you permit any IP traffic to given host?

Jarek

Review Cisco Networking for a $25 gift card