<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cisco PIX: Allow traffic to an internal host</title>
	<atom:link href="http://www.tech-recipes.com/rx/353/cisco-pix-allow-traffic-to-an-internal-host/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tech-recipes.com/rx/353/cisco-pix-allow-traffic-to-an-internal-host/</link>
	<description>Computer and technology tutorials and guides</description>
	<lastBuildDate>Sun, 22 Nov 2009 02:44:39 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: douglassh</title>
		<link>http://www.tech-recipes.com/rx/353/cisco-pix-allow-traffic-to-an-internal-host/comment-page-1/#comment-4591</link>
		<dc:creator>douglassh</dc:creator>
		<pubDate>Tue, 28 Oct 2008 15:24:42 +0000</pubDate>
		<guid isPermaLink="false">guid-fix-me!#comment-4591</guid>
		<description>Well done .&lt;br&gt;Regards&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://xtupload.com&quot; title=&quot;host image free&quot;&gt;host image free&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Well done .<br />Regards</p>
<p><a href="http://xtupload.com" title="host image free">host image free</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Flibble</title>
		<link>http://www.tech-recipes.com/rx/353/cisco-pix-allow-traffic-to-an-internal-host/comment-page-1/#comment-579</link>
		<dc:creator>Flibble</dc:creator>
		<pubDate>Wed, 08 Sep 2004 02:47:05 +0000</pubDate>
		<guid isPermaLink="false">guid-fix-me!#comment-579</guid>
		<description>or rather ICMP doesn&#039;t JUST equal PING.  Opening up all of the ICMP protocol allows source quenches, router redirection and a whole host of stuff that can cause problems.  If all that is required is PING then restrict the traffic to echo request &lt;-&gt;echo reply.</description>
		<content:encoded><![CDATA[<p>or rather ICMP doesn&#8217;t JUST equal PING.  Opening up all of the ICMP protocol allows source quenches, router redirection and a whole host of stuff that can cause problems.  If all that is required is PING then restrict the traffic to echo request &lt;-&gt;echo reply.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: </title>
		<link>http://www.tech-recipes.com/rx/353/cisco-pix-allow-traffic-to-an-internal-host/comment-page-1/#comment-201</link>
		<dc:creator></dc:creator>
		<pubDate>Wed, 09 Jun 2004 10:47:50 +0000</pubDate>
		<guid isPermaLink="false">guid-fix-me!#comment-201</guid>
		<description>Sorry I should have posted this above.  Cisco has a tool on their website to help in converting conduits to ACLs.  It works pretty well but YMMV.  &lt;span style=&quot;text-decoration:underline&quot;&gt;Always&lt;/span&gt; check the configuration file afterward.

Online tool:
https://cco-dev.cisco.com/cgi-bin/Support/OutputInterpreter/home.pl

Downloadable tool if you have a CCO login:
http://www.cisco.com/cgi-bin/tablebuild.pl/pix

-Tom</description>
		<content:encoded><![CDATA[<p>Sorry I should have posted this above.  Cisco has a tool on their website to help in converting conduits to ACLs.  It works pretty well but YMMV.  <span style="text-decoration:underline">Always</span> check the configuration file afterward.</p>
<p>Online tool:<br />
<a href="https://cco-dev.cisco.com/cgi-bin/Support/OutputInterpreter/home.pl" rel="nofollow">https://cco-dev.cisco.com/cgi-bin/Support/OutputInterpreter/home.pl</a></p>
<p>Downloadable tool if you have a CCO login:<br />
<a href="http://www.cisco.com/cgi-bin/tablebuild.pl/pix" rel="nofollow">http://www.cisco.com/cgi-bin/tablebuild.pl/pix</a></p>
<p>-Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: </title>
		<link>http://www.tech-recipes.com/rx/353/cisco-pix-allow-traffic-to-an-internal-host/comment-page-1/#comment-200</link>
		<dc:creator></dc:creator>
		<pubDate>Wed, 09 Jun 2004 10:40:49 +0000</pubDate>
		<guid isPermaLink="false">guid-fix-me!#comment-200</guid>
		<description>FYI: ACL&#039;s were added in IOS 5.3.  All major releases after 6.3 have dropped support for conduits and you must use ACLs.</description>
		<content:encoded><![CDATA[<p>FYI: ACL&#8217;s were added in IOS 5.3.  All major releases after 6.3 have dropped support for conduits and you must use ACLs.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
