• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 346
  • Last Modified:

Allow connection from entire subnet


I am using pix 515E  version 6.3. At present I have allowed connection from and I want to change this and I want to allow entire subnet 161.168.202 and 161.165.228 to ensure any future upgrades will not affect me. What should I do to allow above subnet and at the same time I want to remove old settings.

2 Solutions
Is the 161.165 addresses on the inside going outside?   Or outside wanting to come inside?  

The difference is that the inside to out access list can be easily changed from 'host' to ''  thus allowing every IP in that subnet outbound rights.  

Now if the connection is inbound, then it's not going to work the same way.  For an outside public ip to come inside to a host you need to create either a static map or a port forward to the internal host.     The outside to inside access list could then allow  '' to hit the destination IP you statically mapped.      If you want every 161 ip to hit every internal ip, that's not really a good solution.  You should then look into a peer 2 peer vpn setup instead.

My 2 cents.
This will allow source from those ip's coming from inside to anywhere

access-list TO_FW<--FROM_INSIDE permit ip any
access-list TO_FW<--FROM_INSIDE permit ip any

access-group TO_FW<--FROM_INSIDE in interface inside
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now