Firewall Wizards mailing list archives

PIX Firewall IP Addresses


From: "Mark McCreary" <MMcCreary () tax state va us>
Date: Thu, 17 Oct 2002 10:40:53 -0400

We are using a CISCO PIX firewall version 5.2(5), with both NAT and PAT 
enabled.  My task is to clean-up/reduce the number of conduit rules.  I am 
new at this. 

While reviewing the rules in place, I noticed many cases where individual 
rules are written for consecutive IP addresses.  My question is whether 
the syntax allows for a "range" of addresses to be used in one rule.  For 
example,

Rules written to allow access from source addresses - 172.165.50.200, 
172.165.50.201, 172.165.50.202

Can a source address on one rule replace the 3 rules above, such as 
172.165.50.200-202

Thank you for any assistance.

Regards,

Mark McCreary
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: