cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
517
Views
0
Helpful
1
Replies

IOS Reflexive ACL vs PIX Stateful Firewall

rj
Level 1
Level 1

Is there a substantial security difference between using reflexive ACLs for IP session filtering in IOS and the stateful firewall technology of the PIX?

Thanks,

RJ

1 Reply 1

nkhawaja
Cisco Employee
Cisco Employee

A very basic difference I can tel lyou is that reflexive access-list works for single channel protocols, e.g. http and only supports uptil transport layers of OSI model. Where as PIX firewall and IOSFW does support multi channel protocols (e.g. FTP) and supports inspection uptil application layer.

I hope this will get you started.

Thanks

Nadeem

Review Cisco Networking for a $25 gift card