Allow connection from entire subnet

Experts

I am using pix 515E  version 6.3. At present I have allowed connection from 161.165.202.29 and 161.165.202.28. I want to change this and I want to allow entire subnet 161.168.202 and 161.165.228 to ensure any future upgrades will not affect me. What should I do to allow above subnet and at the same time I want to remove old settings.

lotusboyAsked:
Who is Participating?
 
MikeKaneConnect With a Mentor Commented:
Is the 161.165 addresses on the inside going outside?   Or outside wanting to come inside?  

The difference is that the inside to out access list can be easily changed from 'host 161.165.202.26' to '161.165.202.0 255.255.255.0'  thus allowing every IP in that subnet outbound rights.  

Now if the connection is inbound, then it's not going to work the same way.  For an outside public ip to come inside to a host you need to create either a static map or a port forward to the internal host.     The outside to inside access list could then allow  '161.165.202.0 255.255.255.0' to hit the destination IP you statically mapped.      If you want every 161 ip to hit every internal ip, that's not really a good solution.  You should then look into a peer 2 peer vpn setup instead.

My 2 cents.
0
 
cosmicfoxConnect With a Mentor Commented:
This will allow source from those ip's coming from inside to anywhere

access-list TO_FW<--FROM_INSIDE permit ip 161.168.202.0 255.255.255.0 any
access-list TO_FW<--FROM_INSIDE permit ip 161.165.228.0 255.255.255.0 any

access-group TO_FW<--FROM_INSIDE in interface inside
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.