11-11-2003 05:11 AM - edited 02-20-2020 11:05 PM
I am faced with converting the conduit statements on our PIX 520 to access-lists. Is there a preferred way to do this will as little interuption to traffic as possible? For example, do I create the access-lists, then remove the conduit, or the opposite?
Secondly, is there a recommended precedence in the ordering of the access-list?
Solved! Go to Solution.
11-11-2003 05:30 AM
Hi,
Here's a very good document on converting conduits to ACLs, also when writing ACLs always have your most important ACLs on top of the list as ACLs work from top down. When you make changes to ACLs or Static lines always issue command clear xlate and save with command write memory.
http://www.giac.org/practical/GSEC/Bill_Donaldson_GSEC.pdf - By Bill Donaldson, GSEC.
If you need more inf/help then let me know.
Thanks / Jay.
11-11-2003 05:30 AM
Hi,
Here's a very good document on converting conduits to ACLs, also when writing ACLs always have your most important ACLs on top of the list as ACLs work from top down. When you make changes to ACLs or Static lines always issue command clear xlate and save with command write memory.
http://www.giac.org/practical/GSEC/Bill_Donaldson_GSEC.pdf - By Bill Donaldson, GSEC.
If you need more inf/help then let me know.
Thanks / Jay.
11-11-2003 12:41 PM
Below is the url for Cisco's conduit to acl conversion tool:
http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mgt_pix/pix_111/user_gd/px_conv.htm
If this answer your question please close and rate
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: