Possible Crypto overlap and NAT ACL open to the vs host subnet

Hello

For a PIX 515E 6.3 (5)

I have the following ACL:

List of crypto ACL

ipsectraffic list of allowed access host ip 192.168.7.221 object-group pdvcorp-backup3-to-db1-datacenter
ipsectraffic list of allowed access host ip 192.168.7.222 object-group pdvcorp-backup3-to-db1-datacenter
permit ipsectraffic of the object-group corphosts-datacenter 192.168.10.0 ip access list 255.255.255.0
ipsectraffic permit access list ip object-group Productionhosts - data center object-group access-productionhosts-data center

In the list above Crypto ACL list, hosts, 192.168.7.221 and 192.168.7.222 are both also part of the group 'productionhosts-datacenter"referenced in the same object list ACL. What are the consequences of having the same hosts referenced in the Crypto ACL, if any?

No NAT access list

IP 192.168.7.0 allow Access-list sheep 255.255.255.0 192.168.10.0 255.255.255.0

In regards to the Crypto ACL above, is there a (security wise or another) problem with the opening of the entire subnet with an ACL sheep to save on the duty to nail each host.

Thank you

Dan

It's okay, you can use the same source to multiple destinations.  No issues with the sheep.

Tags: Cisco Security

Similar Questions

Maybe you are looking for