10-29-2009 10:38 AM - edited 03-11-2019 09:34 AM
I have an old Cisco pix 515r v6.3
I need to permit a range of IP's to our mail server on port 25 (only this range should be able to access PORT 24 on the mail server). I'm not very familiar with the PIX, so any help with this would be appreciated. What would the command look like?
Thanks!
10-29-2009 10:43 AM
You can create an object-group.
object-group network permit_smtp
network-object host 1.1.1.1
network-object host 2.2.2.2
network-object 4.4.4.0 255.255.255.0
Then you apply the object group in the ACL.
access-list outside_access extended permit tcp object-group permit_smtp host [your host] eq 24
Hope that helps.
10-29-2009 10:56 AM
Thank you very much! That works perfectly.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide