10-31-2003 03:00 PM - edited 02-20-2020 11:04 PM
Will "conduit permit ip host 1.1.1.1 any" permit out of state packets to host 1.1.1.1?
In asymetric routing scenario with two independent PIXes, inside host 1.1.1.1 (assume it is a valid public address, no NAT) starts connection to a destination outside. Will the PIX that sees ONLY session's inbound traffic to 1.1.1.1 permit it based on the above conduit statement?
Thanks
Jarek
11-01-2003 04:27 AM
No, PIX will not permit out of state packets in. The packets, for a given session, must exit and enter through the same pix.
HTH
11-03-2003 07:33 AM
Are you sure?
The conduit allows ANY IP traffic.
If not, how would you permit any IP traffic to given host?
Jarek
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide