Firewall Wizards mailing list archives

Re: PIX: immediately applying access rules to established connections


From: "R. DuFresne" <dufresne () sysinfo com>
Date: Fri, 16 Jun 2006 14:28:25 -0400 (EDT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



rebot or recycle the firewall will do the trick.

Or drop all open connections and make them re-establish.  not really 
rocket sience, kinda like users on a unix server, you make changes to teir 
env and or login credentials and they are not picked up till the uses 
logsout and back in.

thanks,

Ron DuFresne


On Wed, 14 Jun 2006, Vahid Pazirandeh wrote:

Hi all,

I noticed that after I made some changes to my access-lists with a PIX 7.1(2),
the rules only applied to new connections being made.  The connections that
were already established (like tcp sessions) were unfortunately not affected.

How can I affect all currently established connections with my new access-list
rules?  Is there a "clear" command that'll do the trick?

Thanks for reading. :-)

-Vahid

=============================================
"Make it better before you make it faster."
=============================================

__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


- -- 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         admin & senior security consultant:  sysinfo.com
                         http://sysinfo.com
Key fingerprint = 9401 4B13 B918 164C 647A  E838 B2DF AFCC 94B0 6629

...We waste time looking for the perfect lover
instead of creating the perfect love.

                 -Tom Robbins <Still Life With Woodpecker>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFEkvhMst+vzJSwZikRAvU/AJ9+bgoBHYQfG+p11ORRk3AmTNo9uwCdEyZi
dyf1FKHF6LFjRkm2SyI7qHI=
=fbZJ
-----END PGP SIGNATURE-----
_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: