Solved

Allow connection from entire subnet

Posted on 2009-04-09
2
341 Views
Last Modified: 2012-06-22
Experts

I am using pix 515E  version 6.3. At present I have allowed connection from 161.165.202.29 and 161.165.202.28. I want to change this and I want to allow entire subnet 161.168.202 and 161.165.228 to ensure any future upgrades will not affect me. What should I do to allow above subnet and at the same time I want to remove old settings.

0
Comment
Question by:lotusboy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 250 total points
ID: 24107298
Is the 161.165 addresses on the inside going outside?   Or outside wanting to come inside?  

The difference is that the inside to out access list can be easily changed from 'host 161.165.202.26' to '161.165.202.0 255.255.255.0'  thus allowing every IP in that subnet outbound rights.  

Now if the connection is inbound, then it's not going to work the same way.  For an outside public ip to come inside to a host you need to create either a static map or a port forward to the internal host.     The outside to inside access list could then allow  '161.165.202.0 255.255.255.0' to hit the destination IP you statically mapped.      If you want every 161 ip to hit every internal ip, that's not really a good solution.  You should then look into a peer 2 peer vpn setup instead.

My 2 cents.
0
 
LVL 6

Assisted Solution

by:cosmicfox
cosmicfox earned 250 total points
ID: 24107300
This will allow source from those ip's coming from inside to anywhere

access-list TO_FW<--FROM_INSIDE permit ip 161.168.202.0 255.255.255.0 any
access-list TO_FW<--FROM_INSIDE permit ip 161.165.228.0 255.255.255.0 any

access-group TO_FW<--FROM_INSIDE in interface inside
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Suggested Courses

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question