?
Solved

Cisco PIX Filter Allow commands to allow a RANGE of IPs

Posted on 2006-12-01
8
Medium Priority
?
451 Views
Last Modified: 2013-11-16
I have 300 IPs I need to add to the PIX filter this week.
most are in ranges (ie, xxx.xxx.xxx.1 through xxx.xxx.xxx.50) over about 6 subnets
so, I'm hoping for a way to allow a range rather than doing 300 individual lines of code. Maybe cut it to about 10 or 20
0
Comment
Question by:jskewes
  • 3
  • 3
  • 2
8 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 18055264
You can only group by subnet masks.
0
 

Author Comment

by:jskewes
ID: 18055392
so, I have to do 300 lines of code?
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 1000 total points
ID: 18055535
Pretty much. You might want to create object groups if there is any change that different rules get applied to different IPs or groups of IPs
Which model PIX and what OS version?
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:jskewes
ID: 18055603
PIX 515
not sure of OS version
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 18060605
Adding 300 lines of similar code shouldn't be too much of a headache?  You can manipulate using notepad/cut/copy/paste, and then copy and paste the notepad output straight into your telnet window.
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 18060608
PS - There are NO shortcuts in security !!  :)
0
 

Author Comment

by:jskewes
ID: 18060893
in good security anyway...
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 18060943
We can do port ranges in access-lists, but not source or destination ip address ranges. Only subnets.
At least with the 515 you have enough horsepower to parse through them all. I hope you're using turbo acls....
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
Suggested Courses

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question