cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2801
Views
0
Helpful
2
Replies

Stateful firewall vs reflexive ACL

rj
Level 1
Level 1

Is there a substantial security difference between using reflexive ACLs for IP session filtering in IOS and the stateful firewall technology of the PIX?

Thanks,

RJ

2 Replies 2

jsivulka
Level 5
Level 5

Yes, From what I've read (in bits and pieces), Reflexive ACL's suffer from a number of performance issues. While routers with ACL's (or even better,a router with the firewall feature set) will protect your network to a great degree, I feel a firewall is a must if you are thinking about a strong, long-term security solution.

Thanks for the post. While I know reflexive ACL's will be slower, I still think they are better protection than just regular ACLs. An example is that they will not allow connections started from the outside.

Thanks,

RJ