cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1719
Views
0
Helpful
3
Replies

Checkpoint to ASA Conversion (negate ability in Checkpoint)

campbech1
Level 1
Level 1

I am in the middle of a Checkpoint to ASA conversion and so far it's gone pretty well.

My current problem though is that Checkpoint allowed for me to create an ACL that I could specify a group I created called RFC_1918_Group would not be allowed coming in my outside int but everything else would be allowed.

Any way to do this in the ASA without creating a permit statement along with a deny statement?

Attached is what the rule looks like in Checkpoint.

Thanks in advanced! This could cut down my rule base by a few lines.

3 Replies 3

whisperwind
Level 1
Level 1

There is no predefinied RFC1918 grouping in the ASA

There is NO RFC1918 in checkpoint either.

The user has to create that.

What he is asking will require two separate

line of groups to do the trick. The first

line in the ACL should block RFC1918 addresses

while the second ACL line permit from Any.

Pix ACL is dumb, it is not smart as checkpoint

policy.

Thank you Kevin. That is what I thought but was hoping the ASA was smarter then that.

Two ACLs it is then.

Thanks again.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card