cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
450
Views
0
Helpful
1
Replies

Permit IP on Inside Interface?

firechicken
Level 1
Level 1

If you are not going to restrict access from your internal network to an external network, is there any point of having a 'permit ip any any' on a PIX's inside interface?

1 Reply 1

mostiguy
Level 6
Level 6

you only have permit ip any any in the context of an ACL, if there is an ACL bound to the inside interface, everything will be blocked by default. If all you have in an acl with permit ip any any for the inside int, you can remove the access-group command that binds it to the inside int