Hi,if you need outbound connection for those specific hosts, the only way is to permit them in your acl, because that is the place where your packet is inspected at the first time. So, the static will not work if your acl does not allow the traffic g...
Hi,ICMP is connectionless protocol, so the is entry in the state-table. This means that PIX does not recognize the reply-packet and it treats it as a new connections. So if you use acls, you have to permit icmp in both interfaces, if you use conduit ...
Hi,apply another outbound list to the inside interface. There can be more than one outbound group applied in one interface. If you need to permit few and deny many users, use "outbound 11 deny 0 0" and after that permit particular hosts. As you know...