Network range on PIX

Sep 22, 2005 1 Replies

Does the PIX not support some equivalent of the filter masks used on Cisco routers to define specific networks of a subnet? How would I define, for instance, the 3rd network of a x.x.x.0 255.255.255.240 subnet (x.x.x.32 network using IPs x.x.x.33 through x.x.x.36 (.37 broadcast)) for access control purposes? I see you can list all IPs and then group them but I was hoping for a filter mask equivalent.



Thanks in advance.



In article , Nate wrote: :Does the PIX not support some equivalent of the filter masks used on :Cisco routers to define specific networks of a subnet? How would I :define, for instance, the 3rd network of a x.x.x.0 255.255.255.240 :subnet (x.x.x.32 network using IPs x.x.x.33 through x.x.x.36 (.37 :broadcast)) for access control purposes? I see you can list all IPs :and then group them but I was hoping for a filter mask equivalent.

In access-lists, you would use x.x.x.32 255.255.255.240

There are some commands on the PIX that expect a host IP instead of a network IP and mask. Those commands mostly have to do with access to the PIX itself. None of those commands permit an object-group in the relevant position.

One thing to be aware of is that if you use a netmask of other than

255.255.255.255 in a "static" command, then the PIX will treat the resulting range as if it were a real subnet: it will assume that there should be no traffic sourced from the base address or high address of the range, and will reject packets that show up with those sources [unless you take special steps.] This is the only place that this is true; in ACL contexts, an address and mask is just a handy way to list a complete range.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required