We help IT Professionals succeed at work.

Check out our new AWS podcast with Certified Expert, Phil Phillips! Listen to "How to Execute a Seamless AWS Migration" on EE or on your favorite podcast platform. Listen Now

x

PIX Firewall 6.3: Site-to-Site VPN

Medium Priority
738 Views
Last Modified: 2012-05-11
When configuring site-to-site or remote access VPN with Cisco PIX firewall version 6.3, we normally see the access-list in the form below:
access-list 101 permit ip 1.1.1.0 255.255.255.0 2.2.2.0 255.255.255.0

Can I put it this way?
access-list 101 permit tcp host 1.1.1.1 2.2.2.0 255.255.255.0 eq 3389

Actually I want to limit the access between two ends to some ports, instead of opening all. Is this the correct way for this purpose?
Comment
Watch Question

CERTIFIED EXPERT

Commented:
Yes, you can narrow the access list to specific ports.

The access lists have to match conversely on each end though, so you will need to change the access list on the other end to:

access-list 101 permit 2.2.2.0 255.255.255.0 eq 3389 host 1.1.1.1
Jimmy Larsson, CISSP, CEHNetwork and Security consultant
Commented:
Unlock this solution with a free trial preview.
(No credit card required)
Get Preview
CERTIFIED EXPERT
Commented:
Unlock this solution with a free trial preview.
(No credit card required)
Get Preview

Author

Commented:
How about for PIX version 6.3?
Network and Security consultant
Commented:
Unlock this solution with a free trial preview.
(No credit card required)
Get Preview

Author

Commented:
I mean what would be the right way to filter IPSec traffic in PIX version 6.3.
CERTIFIED EXPERT

Commented:
For 6.3 I think the only way is to create an IP-based VPN, and then use access control lists applied to the interface to filter the traffic.
Jimmy Larsson, CISSP, CEHNetwork and Security consultant

Commented:
That is correct. For such an old version the only way is to filter traffic from inside-network.

/Kvistofta
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a free trial preview!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.