05-15-2003 08:17 AM - edited 03-09-2019 03:18 AM
I have DMZ1 (security50) which needs access to DMZ2 (security20). However, for this access to work I need to modify the access-list which controls access from DMZ1 to Inside (security 100). My understanding was that you only needed access-list statements for access from low-to-high not high-to-low.
Have I simply misunderstood this?
Solved! Go to Solution.
05-15-2003 09:04 AM
Andrew,
In general what you are saying is true. This is how the PIX is designed. But, once you apply the acl on the higher security interface whether its inside or dmz, that default behavior no longer there. In that case, you need to exclusively allow the traffic from higher to lower. So, this is the flexibility we as security engineer have to control our traffic from our strictly secured LAN. Although, we know that inside is always secured, but an acl can be applied to control which traffic is allowed to the outside or dmz. Your case is an classic exmple of why you need an acl from higher to lower security interface.
I hope this helps ! Thanks,
Mynul
05-15-2003 09:04 AM
Andrew,
In general what you are saying is true. This is how the PIX is designed. But, once you apply the acl on the higher security interface whether its inside or dmz, that default behavior no longer there. In that case, you need to exclusively allow the traffic from higher to lower. So, this is the flexibility we as security engineer have to control our traffic from our strictly secured LAN. Although, we know that inside is always secured, but an acl can be applied to control which traffic is allowed to the outside or dmz. Your case is an classic exmple of why you need an acl from higher to lower security interface.
I hope this helps ! Thanks,
Mynul
05-16-2003 12:07 AM
Thanks for the reply - I suspected as much (i.e. that the default behaviour changes after applying an access-list) but it doesn't appear to be documented anywhere. It's nice to know that it's by design!
Andrew.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide