<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Tech-Recipes - Latest Comments in Cisco PIX: Allow traffic to an internal host | Cisco firewall | Tech-Recipes</title><link>http://tech-recipes.disqus.com/</link><description>Cookbook of Tech Tutorials</description><language>en</language><lastBuildDate>Tue, 07 Sep 2004 22:47:05 -0000</lastBuildDate><item><title>Re: Cisco PIX: Allow traffic to an internal host | Cisco firewall | Tech-Recipes</title><link>http://www.tech-recipes.com/rx/353/cisco-pix-allow-traffic-to-an-internal-host/#comment-2767361</link><description>or rather ICMP doesn't JUST equal PING.  Opening up all of the ICMP protocol allows source quenches, router redirection and a whole host of stuff that can cause problems.  If all that is required is PING then restrict the traffic to echo request &amp;lt;-&amp;gt;echo reply.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Flibble</dc:creator><pubDate>Tue, 07 Sep 2004 22:47:05 -0000</pubDate></item><item><title>Re: Cisco PIX: Allow traffic to an internal host | Cisco firewall | Tech-Recipes</title><link>http://www.tech-recipes.com/rx/353/cisco-pix-allow-traffic-to-an-internal-host/#comment-2767360</link><description>Sorry I should have posted this above.  Cisco has a tool on their website to help in converting conduits to ACLs.  It works pretty well but YMMV.  &amp;lt;span style="text-decoration:underline"&amp;gt;Always&amp;lt;/span&amp;gt; check the configuration file afterward.&lt;br&gt;&lt;br&gt;Online tool:&lt;br&gt;&lt;a href="https://cco-dev.cisco.com/cgi-bin/Support/OutputInterpreter/home.pl" rel="nofollow"&gt;https://cco-dev.cisco.com/cgi-bin/Support/Outpu...&lt;/a&gt;&lt;br&gt;&lt;br&gt;Downloadable tool if you have a CCO login:&lt;br&gt;&lt;a href="http://www.cisco.com/cgi-bin/tablebuild.pl/pix" rel="nofollow"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/pix&lt;/a&gt;&lt;br&gt;&lt;br&gt;-Tom</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Wed, 09 Jun 2004 06:47:50 -0000</pubDate></item><item><title>Re: Cisco PIX: Allow traffic to an internal host | Cisco firewall | Tech-Recipes</title><link>http://www.tech-recipes.com/rx/353/cisco-pix-allow-traffic-to-an-internal-host/#comment-2767359</link><description>FYI: ACL's were added in IOS 5.3.  All major releases after 6.3 have dropped support for conduits and you must use ACLs.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Wed, 09 Jun 2004 06:40:49 -0000</pubDate></item></channel></rss>