Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Allow connection from entire subnet

Posted on 2009-04-09
2
Medium Priority
?
343 Views
Last Modified: 2012-06-22
Experts

I am using pix 515E  version 6.3. At present I have allowed connection from 161.165.202.29 and 161.165.202.28. I want to change this and I want to allow entire subnet 161.168.202 and 161.165.228 to ensure any future upgrades will not affect me. What should I do to allow above subnet and at the same time I want to remove old settings.

0
Comment
Question by:lotusboy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 1000 total points
ID: 24107298
Is the 161.165 addresses on the inside going outside?   Or outside wanting to come inside?  

The difference is that the inside to out access list can be easily changed from 'host 161.165.202.26' to '161.165.202.0 255.255.255.0'  thus allowing every IP in that subnet outbound rights.  

Now if the connection is inbound, then it's not going to work the same way.  For an outside public ip to come inside to a host you need to create either a static map or a port forward to the internal host.     The outside to inside access list could then allow  '161.165.202.0 255.255.255.0' to hit the destination IP you statically mapped.      If you want every 161 ip to hit every internal ip, that's not really a good solution.  You should then look into a peer 2 peer vpn setup instead.

My 2 cents.
0
 
LVL 6

Assisted Solution

by:cosmicfox
cosmicfox earned 1000 total points
ID: 24107300
This will allow source from those ip's coming from inside to anywhere

access-list TO_FW<--FROM_INSIDE permit ip 161.168.202.0 255.255.255.0 any
access-list TO_FW<--FROM_INSIDE permit ip 161.165.228.0 255.255.255.0 any

access-group TO_FW<--FROM_INSIDE in interface inside
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
Will you be ready when the clock on GDPR compliance runs out? Is GDPR even something you need to worry about? Find out more about the upcoming regulation changes and download our comprehensive GDPR checklist today !
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question