Internet Access PIX

bbresslin
bbresslin used Ask the Experts™
on
I need to set up an ACL in an Pix, that allows a certain range of IP addresses access to the internet, however I need to allow all ip addresses access across the site to site VPN, is there an access rule I can set up to allow the range of IP's access to the internet, while still allowing the other ips access across the site to site VPN?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Sr. Systems Engineer
Top Expert 2008
Commented:
Use an acl in this form:
access-list Internet permit ip host a.b.c.d any
access-list Internet permit ip host a.b.c.e any
access-list Internet permit ip host a.b.c.a any
access-list Internet permit ip a.b.c.0 255.255.255.0 d.e.f.0 255.255.255.0
access-group Internet in interface inside

Where a.b.c.0 = local inside LAN and d.e.f.0 is remote lan across the VPN tunnel

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial