Routing based on the source in PIX

Hello

I am trying to find a way to make a routing based on the PIX source to get the same functionality of the 'road-map' command in Cisco routers; is there an equivalent command for this PIX 7.x version? I remember that it was not available in previous versions and I couldn't discover version 7.x, also, but I wanted to confirm with you double.

Thanking in advance.

Kind regards

Haitham

Haitham,

Your interpretation is correct, Policy Based Routing is not supported on the Pix Firewall.

Also, don't you confused when you see the command option 'road-map' Pix 6.3 and higher. This command is applicable only when redistributing routes into OSPF.

6.3 Pix command reference:

http://www.Cisco.com/univercd/CC/TD/doc/product/iaabu/PIX/pix_sw/v_63/cmdref/Mr.htm#wp1017196

Command reference 7.2 pix

http://www.Cisco.com/univercd/CC/TD/doc/product/multisec/asa_sw/v_7_2/cmd_ref/qr_711.htm#wp1648744

Let me know if it helps.

Kind regards

Arul

Tags: Cisco Security

Similar Questions

  • Route based on the ID of the virtual Port of departure

    Hi all

    Our client uses 'Route based on originating Virtual Port ID' to balance the load. Ayone know the ESX CLI command that shows the Virtual Machine <>= vmnic in this setting?

    There was a network problem in the customer environment, and I need to know what VM is linking to what (vmnic) uplink on the vswitch about? Or ESX does not show this explicit mapping through any tool?

    Thanks in advance.

    Dumlu

    Hello

    You can use esxtop, then hit low case n to change the network settings view. The 3rd column is the team of Teddy bear used by the virtual machine.

    Concerning

  • Based on the sources, the routing of calls on VCS - E

    Hello

    We have now several customers, who can dial only an IP address. Is there a way to do a based ip source routing?

    Example:

    source ip address: 1.1.1.1. dest ip: 10.10.10.10 (VCS-E)--> translated destination: [email protected] / * /

    source ip address: 2.2.2.2. dest ip: 10.10.10.10(VCS-E)--> translated destination: [email protected] / * /

    source ip address: 3.3.3.3. dest ip: 10.10.10.10(VCS-E)--> translated destination: [email protected] / * /

    Translated destinations are known by the VCS-E.

    Best regards

    Daniel

    Maybe you're using the CPL, take a look at the start on pg 345 VCS Admin Guide .

    What endpoints they use and how they are deployed that restrict them to compose only via IP address?

  • SFR - no policy of the 'rate of bandwidth limit' based on the source IP address

    Hello security experts.

    I can't find the policy of depending on source IP bandwidth rate limiting or a device of the type (in the case of mobile devices android or apple) on SFR because it was easily configurable with the CX on ASA5515-X module.

    Anyone know if I can put it on Firesight and SFR sensor ASA5515-X?

    Thanks in advance.

    Kind regards

    Remi

    Remi,

    Unfortunately the limit speed of bandwidth / traffic shaping is not currently available for devices of firepower.

    You can speak to your sales representative to discuss the future roadmap of the produ

    CT in more detail.

    The function is in the road map and will come with the future software release 6.X.

    Best regards

    Veronika

  • Cisco ASA 5510 - restrictions of VPN (AnyConnect) based on the AD user or IP address

    Hello

    I want to test how to restrict access user on an ASA 5510 AnyConnect. In politics, I can define what networks will go through the VPN tunnel and which not (split tunneling). The ASA has a LDAP connection and only AD users with a special security group can connect over AnyConnect.
    On the other hand I would like to restrict access for special users within a VPN policy.

    So my question:
    What are your recommendations to implement this szenario?

    My two ideas would be:
    1. the access rules based on the user of the AD.
    2. special reserve IP addresses in the pool of addresses AnyConnect for some users, so I can limit access to the normal firewall rules base based on the source IP address.

    What are your recommendations and is it possible to realize my ideas (and how)?

    Thanks in advance

    Best regards

    Hello

    I will suggest that you configure a second ad group in the server and another group strategy in the ASA, you can configure certain access on each group policy "the installer of the filters, assign different split political tunnel, different ACL' and in the ad server, you can assign users for example to the AD Group A and AD Group B based on the access you want to give them now , you must configure LDAP mapping to assign the user specific group policy that you want based on the AD group that they belong.

    You can follow this documentation that will help you configure the LDAP Mapping:

    http://www.Cisco.com/c/en/us/support/docs/security/ASA-5500-x-series-NEX...

    Best regards, please rate.

  • Conditional routing based on user or node access group

    We have a requirement to send a DRG application to a specific approver based on the issuing user or group access to the node of the issuer.  Is it possible to refer to the Group of access user or node in a formula derived from property or the validation that I could use in conditional routing in 11.1.2.4?

    I recently discovered the function UserName().  I have built a hierarchy of users DRG and can use the function UserName() to tie in to the values to use in a conditional routing based on the current user.

  • Routing of calls based on the area Code

    I want to route the calls to some agents based on the caller's area code. I guess I'll need a database file to reference the calling party number. Then filter on the area code and the router accordingly. I never did look a script on a database. I would use a separate SQL database server for this.

    I can handle the routing part as soon as I know not if the number of matches. I just need some advice on getting to the database correctly.

    If I'm heading in the wrong direction? It must be an XML file instead? All the sample scripts or tips would be appreciated.

    No problem. Remember not all the nifty tools in the method Execute of Java later and I think that you will find very practical in many scenarios.

    Moreover, do not forget if you find a post is useful or solve your problem, you should give him a side :)

    Thank you

    Jim

  • SQL query to find the total number of source based nonsource passangersbetween source and destination station and passenger station on the same chekindate

    Hello

    SQL query to find the total number of source based nonsource passangersbetween source and destination station and passenger station on the same chekindate.

    Please help on this script and let me know if you need more details.

    ---

    You use a SELECT statement.  Let me know if you need more details.

  • Internal analysis based on the error Code 7

    I am trying to create the Setup program for one of my application and got stuck with deployment error. Build state indicates as follows

    From a newspaper for the deployment.

    Based on the analysis

    Analysis completed

    Error code internal 7 analysis of departure

    Path must be a directory or a LLB.

    Abandoned

    When you click the Distributor tab, he asks "Do you want to analyze the source files?", when I click OK, it says-" < no="" file="" information,="" analyze="" a="" workspace=""> "

    But it does not give the same problem when I uncheck the "of Teststand public directories' in the Source System tab. But I need to include the public directory to create the installer properly. What could be the problem?

    I created Installer a few months back and its job perfectly well. But now I need to review the sequence, that is why the installation program. But not stuck

    TestStand Version 2012

    Fransico,

    I have re installed Teststand 2012 and the issue has been resolved. could not figure that out what was going on. Then uninstalled Teststand 2012.

  • problem of visarc in the source distribution

    I am trying to build a distribution from source to a project in LabVIEW 8.6.1.  I need to build the source distribution so that I can password protect all VI in the project (about 1200).  When I try to compile the source distribution I get the following error message.

    As you can see the source file does not exist because the path: C:\Documents and Settings\Program NIUninstaller Instruments... does not exist.  So, I created this path and place the visarc file where LabVIEW thinks it should be.  When I Isaiah to compile the source with the wrong path distribution I get the following error message:

    Once more the following path does not exist: Program Files: \Nationa lnstruments\LabVIEW 8.6...

    I don't know how to create this way false because he seems to treat the program as its own hard drive files.

    The next thing I did was reinstall DAQmx 8.9 as the name of the file is visarc, I don't know that it is connected to DAQmx but the visarc makes me think it might be.  DAQmx reinstalling does not fix this error.

    I should also add that I was able to build a very good three weeks ago source distribution.  During the last three weeks the code was treated by myself and two other developers.  I had seen problems with other developers link dll from their office of vi in the library, and when I pulled it back on my machine, I have been unable to build a source distribution, because their DLLs have been at a different path.  I solved this problem of rebind each Subvi to the dll in the correct path.  Could be a similar problem where one of the other developers visarc stored in C:\Documents and Settins\Program files... and I just need to recreate a link to the visarc file?  I don't think so because I don't think "recreate a link to the visarc file" is since then.  I'm open to any feedback.

    Thank you!

    Here is a solution provided by an EA:

    Hi Jon,

    The following information should help you to resolve the error you see

    LabVIEW VIs point to the rc files that are not in the vi.lib.  This means if you move the VI on disk (upward in a folder, in a folder, another drive), then the path that he stored in the rc (relative path) is no longer correct.  The application builder will recognize that the rc file will have two different routes (the one which is correct and which is not).
    Once two different paths are recognized source distributions will not be built successfully.  To correct this problem, follow these steps:
    1. If you have any previous version of LabVIEW installed temporarily
    Rename the folders of their resources.  Directories of resources can be in the labview\resource directory.
    2. Add massCompAll = True in the file LabVIEW.ini version of LabVIEW
    used.  The file is located in labview\LabVIEW.ini.  LabVIEW must be closed when you change the LabVIEW.ini file.
    3. launch LabVIEW, mass compile the project, and then try the build.
    4. exit LabVIEW and difficulty of any renamed resource records again to their
    original name.
    5. remove the massCompAll = True token in the LabVIEW.ini file once the
    compilation of mass is over.
    Note: Rename files from older versions of LabVIEW resources is critical because the token defined otherwise has a chance to cause the vi.lib of the different versions of LabVIEW to be reticulated

    Meghan
    Technical sales engineer
    National Instruments

  • With the source on computer with no Labview distribution

    I'm doing my 700w application. I created an executable file from the main application that runs on a computer with no software of Labview development on it. In this application, I can run the screws which are located on the hard disk in separate folder (sources), or that I have to build an executable for each module?

    What do you call others live? If these screws are already called in the application itself, then they would automatically be enrolled in the executable when you generate them.

    If these are screws that are based on the computer where you run the executable file, you can then run the screw by using VI Server calls in the executable.

  • When you transfer files to the internet, the router disconnects from the internet, but the network remains in tact.

    I have a wireless router Belkin g with 1 Server 2003 cable and 2 xp machines and 1 machine vista wireless. My problem is when you transfer files to the internet, the router disconnects from the internet, but the network remains intact. I cannot remote in all computers, but not internet. Once I have restart the router, everything works fine. I was wondering if anyone else has had this problem and how to fix them.

    original title: problems with the router.

    I have no solution for you.  It seems more likely to me that it is a hardware problem - but if it was related to traffic, I would expect that the problem on the downloads more downloads.

    In addition to DSL reports, you could try to ask some of the forums that specialize in the updated firmware for wireless routers.  This is not to say that you need to install the modified firmware (although there may be good reasons to do so), but people who do usually firmware mods are much how the equipment works and what might be its potential failure modes.

    Is one of the best-known sites DD-WRT.com, but there is one list of other here: http://en.wikipedia.org/wiki/List_of_wireless_router_firmware_projects the firmware on these sites was originally designed to run on Modem Linksys WRT54G, but applies generally to Linux with chips Broadcom - based wireless routers and DD - WRT claims that its firmware takes care of some Belkin routers.  If your router is one of those on what DD - WRT will work, there will probably be someone in the forum there will have something for you.  See the list here: http://www.dd-wrt.com/site/support/router-database

  • utility based on the Web shows again the old version of the firmware - HELP PLEASE

    In September of last year, I replaced my old Linksys with a new (BEFSR41 ver 4.3).  I started to get in trouble yesterday, so I consulted the web-based utility and noticed that the window says: the firmware 2.0 version!

    I tried to update to the latest firmware available for my model, following the instructions on the site but something went wrong and the firmware has been altered. Finally, I managed to update the firmware via tftp utility, and he said that the upgrade has gone through. But the utility still shows the version of the firmware 2.0.  Under the router > status reads as follows:

    Capture (share.field_33_UI_share) Firmware Version: 2.00.4 build 7, January 20, 2010

    I am very confused. Which is the latest firmware or I get it confused with the 4.3 version number?

    I really hesitate to update the firmware again after the problems I had the first time.  If anyone can give me some advice on what to do, I would really appreciate it.

    You confuse the hardware version of the router with the version of the firmware.

    The BEFSR41 is the model. One physical versions of this model. Each version contains a different material. The exact hardware version is printed on the label under the router.

    The firmware version is the version of the firmware (software) running on the router. It is important that the firmware used is compatible with the hardware version of the router. For this reason, you must select the correct hardware on the router Linksys support download site version to be sure to choose the right firmware compatible with your router.

    The latest version of the firmware of the BEFSR41 v4.3 is Ver.2.00.4 Build 7. You have the latest firmware.

  • WRT350N configuration based on the web does not load on the cable port.

    I've had this router for over 6 months, and only in the last two weeks, I could not access the configuration page based on the web through my PC, connected to one of the 4 wired ports. None of the laptops I tried (Win XP, Vista) are connected via Wi - Fi without a problem. Obviously, this isn't an emergency, because I can access it through the laptop, but I use mostly my PC to manage the router.

    Any ideas on other things to check?

    Thanks for the tip, but that did not work... However, trying to fix another problem, with the USB port of a storage drive, I re-load the updated firmware and am now able to access the configuration page. Still no action on the USB key if!

    Thanks again!

  • Configure access ssh_key based switch MXL. Not "based on the host."

    I have read the documentation and cannot get to a cohesive whole procedure in order to get the simple key-based authentication to work.

    The docs separate this task in a wide variety of measures in order to activate authentication "host-based", but I don't want to.  I use two laptops and 2 different offices in various locations.  "Host-based" is not going to work for me.  I need an authentication of purely "function key".  You need an example of what involved specific steps and the order to execute them.  I find that this process is pretty simple on the HP based including the new Arubas switches.  But this MXL documentation is difficult to decipher.

    It seems as it is a one-at-a-time operation, but it is more advanced and allows you to better separate, and so I'm happy with it so far.

    1. create the user with administrator privileges
    SN - MXL (conf) "JUtilisateur" somepass privilège 15 password #username

    2 enable authentication rsa
    SN - MXL (conf) ssh rsa authentication #ip activate

    3. copy your public key in the MXL (pull)
    SN - MXL #copy scp: flash:
    Address or name of the host remote []: 172.16.11.10
    Port number of the server [22]:
    Source file name []:.ssh/juser_rsa.pub
    User name to host remote login: "JUtilisateur"
    Password to the remote to connect host:
    The destination [juser_rsa.pub] file name:
    !!
    403 bytes copied successfully

    4. now log in as user, and run:
    SN - MXL #ip ssh juser_rsa.pub my authorized key of rsa authentication
    RSA keys added to the list of authorized Keys user.
    Delete the juser_rsa.pub file: (yes/no)? Yes

    5. I had to create the file ~.ssh/config with the following statement:

    host mxl
    Host name 172.16.11.1
    The user juser
    IdentityFile ~/.ssh/juser_rsa

    This means that the PRIVATE key is referenced.  Note: Make sure that your config file is has 644 permissions.

    6 test

    $ ssh mxl

    The option of SupportAssist EULA acceptance has not been selected. SupportAssist
    can be activated once the EULA of SupportAssist has been accepted. Use of the:
    command "Activate support-assist" to accept the EULA and activate SupportAssist.

    MON-MXL #.

    And I am.  Either way, I want to get rid of that little nag, as this MXL stack is not in a country supported by DELL.  Anyone know how to remove the horse?

Maybe you are looking for

  • iPhone 6 s sound quality changed 10.0.2 w/ios

    After updating my iPhone 6 to 10.0.2 has changed the sound quality of the voice of the people at the other end. It does not resemble a normal call. He has the kind of internet "voice over" quality to it. Is there a setting that may have been changed

  • Can't get HP Office jet to analyze.

    HP Officejet 6500 has AIO.  communication scanner error cannot be established.  All my fine connection. This printer scanner worked fine in my old win xp Dell. New computer Lenovo K series. running Win 7-64.  Installed via disk and also I tried to do

  • HP Pavilion Gaming 15 - ak155nm: problem with detection m.2 SSD

    Hello I built a computer with M.2 Intel SSD 256 GB 600p and for some reason it does not detect the SSD m2. I have HP Pavilion 15 - ak155nm portable Gaming. Please help. Thank you Toni

  • C5580 error message

    HP C5580. Windows 7 operating system. Message reads "Paper Mismatch" even if using paper the same as always. Tried more paper - the same message. Just changed color cartridge. Print, but not copy.

  • Disable (uninstall) zoosk messenger? I have

    I disabled my zoosk account but zoosk messenger opens whenever I turn on my laptop. How can I remove zoosk messenger permenantley, any help please?