Solved

Allow connection from entire subnet

Posted on 2009-04-09
2
334 Views
Last Modified: 2012-06-22
Experts

I am using pix 515E  version 6.3. At present I have allowed connection from 161.165.202.29 and 161.165.202.28. I want to change this and I want to allow entire subnet 161.168.202 and 161.165.228 to ensure any future upgrades will not affect me. What should I do to allow above subnet and at the same time I want to remove old settings.

0
Comment
Question by:lotusboy
2 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 250 total points
Comment Utility
Is the 161.165 addresses on the inside going outside?   Or outside wanting to come inside?  

The difference is that the inside to out access list can be easily changed from 'host 161.165.202.26' to '161.165.202.0 255.255.255.0'  thus allowing every IP in that subnet outbound rights.  

Now if the connection is inbound, then it's not going to work the same way.  For an outside public ip to come inside to a host you need to create either a static map or a port forward to the internal host.     The outside to inside access list could then allow  '161.165.202.0 255.255.255.0' to hit the destination IP you statically mapped.      If you want every 161 ip to hit every internal ip, that's not really a good solution.  You should then look into a peer 2 peer vpn setup instead.

My 2 cents.
0
 
LVL 6

Assisted Solution

by:cosmicfox
cosmicfox earned 250 total points
Comment Utility
This will allow source from those ip's coming from inside to anywhere

access-list TO_FW<--FROM_INSIDE permit ip 161.168.202.0 255.255.255.0 any
access-list TO_FW<--FROM_INSIDE permit ip 161.165.228.0 255.255.255.0 any

access-group TO_FW<--FROM_INSIDE in interface inside
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Like many others, when I created a Windows 2008 RRAS VPN server, I connected via PPTP, and still do, but there are problems that can arise from solely using PPTP.  One particular problem was that the CFO of the company used a Virgin Broadband Wirele…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now