PIX: accept
PDM: warn
A-4 overlap with interface address
ip address outside 192.168.1.1 255.255.255.0
static (inside,outside) 192.168.1.0 1.1.1.0 netmask 255.255.255.0
PIX: accept
PDM: accept
A-5 overlap with global pool
global (outside) 1 192.168.1.1-192.168.1.10
static (inside,outside) 192.168.1.2 1.1.1.2 netmask 255.255.255.255
PIX: accept
PDM: accept
B. Static PAT
B-1 PAT overlap between siblings
static (inside,outside) tcp 1.1.1.1 80 1.1.1.1 8080 netmask 255.255.255.255
static (inside,outside) tcp 1.1.1.1 80 2.2.2.1 80 netmask 255.255.255.255
or
static (inside,outside) tcp 1.1.1.1 80 1.1.1.1 8080 netmask 255.255.255.255
static (inside,outside) tcp 2.2.2.1 80 1.1.1.1 8080 netmask 255.255.255.255
PIX: reject
PDM: reject
B-2 redundant/overlap between children and parent
B-2-1 redundant, child first
static (inside,outside) tcp 1.1.1.1 80 1.1.1.1 8080 netmask 255.255.255.255
static (inside,outside) tcp 1.1.1.0 80 1.1.1.0 8080 netmask 255.255.255.0
PIX: accept
PDM: warn
B-2-2 redundant, parent first
static (inside,outside) tcp 1.1.1.0 80 1.1.1.0 8080 netmask 255.255.255.0
static (inside,outside) tcp 1.1.1.1 80 1.1.1.1 8080 netmask 255.255.255.255
PIX: accept
PDM: warn
B-2-3 overlap, child first
static (inside,outside) tcp 1.1.1.1 80 1.1.1.1 8080 netmask 255.255.255.255
static (inside,outside) tcp 1.1.1.0 80 1.1.1.0 80 netmask 255.255.255.0
PIX: accept
Summary of Contents for PIX 520 - PIX Firewall 520
Page 45: ...Copyright 2001 Cisco Systems Inc ...
Page 68: ...Copyright 2001 Cisco Systems Inc ...
Page 74: ...Copyright 2001 Cisco Systems Inc ...
Page 87: ...Copyright 2001 Cisco Systems Inc ...
Page 92: ...Copyright 2001 Cisco Systems Inc ...
Page 108: ......
Page 184: ......
Page 197: ...Copyright 2001 Cisco Systems Inc ...
Page 200: ......
Page 232: ...Copyright 2001 Cisco Systems Inc ...
Page 246: ...Copyright 2001 Cisco Systems Inc ...