cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1086
Views
0
Helpful
3
Replies

Difference between "conduit" and "access-lists"

willyseo
Level 1
Level 1

Dear all,

I want to know the difference between "conduit" and "access-lists".

When I want to protect packet from outside to inside,

what do you recommend to me? conduit or access-lists?

Thanks advance,

Willy Seo

3 Replies 3

nagle
Level 1
Level 1

I believe while they operate slightly differently they both more or less give you the same result. I remember reading in one of the more recent manuals that they want you to use the Access-lists since conduits are the older way of doing things and they are looking to move away from that to make everything more IOSy

Ben

rstaaf
Level 1
Level 1

Willy,

First if you are trying to decide between using conduits or access lists go with access lists and groups as the conduit will not be around much longer although it still works with PIX v6.01. The access list will allow you to simplify your config as you can create once or few sets of access lists and assign them to multiple devices through access groups. Say for example you had 3 servers behind your pix and you want to allow www, https, smtp and ssh to each of those servers. It would take 12 conduit statements to do that whereas it would take 4 access lists statements and 3 access group statements to do the same thing so you would reduce your config by 5 statements. This is really usefull if you have a large config.

Hope this helps.

Bob

ktgp268
Level 1
Level 1

Are you looking for a boost for your Murrieta, CA, business? Our SEO services are tailored to maximize visibility and help you reach new heights Internet Marketing Murrieta. We provide up-to-date search engine optimization (SEO) services to ensure your business stays ahead of the competition.