PIX access-list versus access-group

Posted on 2007-08-08
Last Modified: 2013-11-16
What is the difference between an access-list and and access-group?
Does an access-group apply to all access lists?  

Just trying to make sense of these commands.. Thanks
Question by:bandoafernandez
    LVL 32

    Accepted Solution

    An access-list is the conditional policy that you define as to what is allowed and what is not.

    an access-group tells the pix on which interface the above access-list needs to be bound and in which direction.

    So taking your old example;

    access-list Outside_In permit tcp any host eq 80

    access-group Outside_In in interface outside

    Here the above access-list tells to allow all tcp connections from any host to host on port 80

    Now, it needs to be bound to an interface so that the pix needs when to use this access-list for checking the traffic. So;

    access-group <Name> <in/out> <interface> <inside/outside/dmz>

    <Name> -> you already know it

    <in/out> -> Tells whether to inspect the traffic if that is coming in (in) or going out (out) of that interface mentioned next

    <inside/outside/dmz> -> Tells on which interface this needs to be applied.

    LVL 32

    Expert Comment

    Did the info I provide help ?


    Author Comment

    Yes, absolutely.  Thanks so much for the clarification!

    Featured Post

    Better Security Awareness With Threat Intelligence

    See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

    Join & Write a Comment

    This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
    Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…
    Sending a Secure fax is easy with eFax Corporate ( First, Just open a new email message.  In the To field, type your recipient's fax number You can even send a secure international fax — just include t…

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    15 Experts available now in Live!

    Get 1:1 Help Now