Access Rules
The Access Rules tab shows your entire network security policy expressed in
rules
. This tab combines the
concepts of
access lists
,
outbound lists
, and
conduits
to describe how a specific
host
or
network
interacts with
another (
host/network
) to permit or deny a specific service and/or protocol. This tab also lets you define
authentication, authorization, or accounting (AAA) rules, and filter rules for ActiveX and Java.
The PIX Firewall uses the Adaptive Security Algorithm (
ASA
) to allow one-way (inside to outside) connections
without an explicit configuration for each internal system and application. The Access Rules tab lets you
configure exceptions to this algorithm, so that certain traffic can access your higher security interfaces.
The Adaptive Security Algorithm is a very
stateful
approach to security. Every inbound packet is checked against
the Adaptive Security Algorithm and against connection state information in memory. This stateful approach to
security is regarded in the industry as being far more secure than a stateless packet screening approach. For more
information, refer to the section "
Adaptive Security Algorithm
" in Chapter 1 "Using PIX Firewall" in the
Cisco
PIX Firewall and VPN Configuration Guide Version 6.1
. You must have access to the Internet for this link to
work.
The following sections are included in this Help topic:
Preparing to Set Up Access Rules
●
Important Notes
●
More Information About Access Rules
●
Implicit Rules
●
Field Descriptions
●
How Rules are Organized
●
Null Rules
●
Example Rule
●
Adding a New Rule
●
Editing a Rule
●
Pasting a Rule
●
Inserting a Rule
●
Reorganizing Rules
●
Deleting a Rule
●
Resetting to Last Applied Settings
●
Summary of Contents for PIX 520 - PIX Firewall 520
Page 45: ...Copyright 2001 Cisco Systems Inc ...
Page 68: ...Copyright 2001 Cisco Systems Inc ...
Page 74: ...Copyright 2001 Cisco Systems Inc ...
Page 87: ...Copyright 2001 Cisco Systems Inc ...
Page 92: ...Copyright 2001 Cisco Systems Inc ...
Page 108: ......
Page 184: ......
Page 197: ...Copyright 2001 Cisco Systems Inc ...
Page 200: ......
Page 232: ...Copyright 2001 Cisco Systems Inc ...
Page 246: ...Copyright 2001 Cisco Systems Inc ...