11-11-2003 05:11 AM - edited 02-20-2020 11:05 PM
I am faced with converting the conduit statements on our PIX 520 to access-lists. Is there a preferred way to do this will as little interuption to traffic as possible? For example, do I create the access-lists, then remove the conduit, or the opposite?
Secondly, is there a recommended precedence in the ordering of the access-list?
Solved! Go to Solution.
11-11-2003 05:30 AM
Hi,
Here's a very good document on converting conduits to ACLs, also when writing ACLs always have your most important ACLs on top of the list as ACLs work from top down. When you make changes to ACLs or Static lines always issue command clear xlate and save with command write memory.
http://www.giac.org/practical/GSEC/Bill_Donaldson_GSEC.pdf - By Bill Donaldson, GSEC.
If you need more inf/help then let me know.
Thanks / Jay.
11-11-2003 05:30 AM
Hi,
Here's a very good document on converting conduits to ACLs, also when writing ACLs always have your most important ACLs on top of the list as ACLs work from top down. When you make changes to ACLs or Static lines always issue command clear xlate and save with command write memory.
http://www.giac.org/practical/GSEC/Bill_Donaldson_GSEC.pdf - By Bill Donaldson, GSEC.
If you need more inf/help then let me know.
Thanks / Jay.
11-11-2003 12:41 PM
Below is the url for Cisco's conduit to acl conversion tool:
http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mgt_pix/pix_111/user_gd/px_conv.htm
If this answer your question please close and rate
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide