Firewall Wizards mailing list archives

Re: Fw: cisco pix does not log traffic targetted to itself?


From: Mark.Boltz () stonesoft com
Date: Sun, 12 Jan 2003 10:42:51 -0500


Hi,

 interface (by default 0 (lower level) is assigned to the outside
interface
 and 100 (higher level) to the inside interface).
 In the normal ACLs there is an implied "deny all" at the end.

i have never liked the ASA/security level approach that PIX uses--i
would rather not have implied policies.  i'm told you can assign

Kevin, I'm not sure I understand. Do you mean you don't want implied
policies in a general sense? In this particular case, we're talking a final
"deny all" rule, which is because the generally accepted stance of security
products should be to deny that which is not expressly permitted. Curious
as to which you meant...

Mark B.
Product Manager, StoneGate
Stonesoft Corp.


_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: