cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
232
Views
0
Helpful
2
Replies

PIX 515 E

gauravprakash
Level 1
Level 1

Hi,

Following info about PIX.

Inside to Outside: If a user from the inside starts a connection to the outside (or to be more precise, to an interface with a lower security level), this connection will by default be permitted, and the return packets of this connection too.

How does the pix knows that an outsider or an insider started a particular connection, which it should deny pr permit.????

2 Replies 2

rais
Level 7
Level 7

For TCP session to start there must be a SYN packet sent from the initiator of the session. If that packet comes from outside, PIX simply discards it and session never comes up.

Hope this helps.

thisisshanky
Level 11
Level 11

You can read more about ASA algorithm here..

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a00800b6f0e.html

Sankar Nair
UC Solutions Architect
Pacific Northwest | CDW
CCIE Collaboration #17135 Emeritus

Review Cisco Networking for a $25 gift card