- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-31-2011 02:29 PM
Recently purchased a PA2020 to replace our Cisco PIX 525. I'm in the process of auditing our cisco config and recreating it in the PA.
I'm looking for suggestions on how to allow applications inside to outside and outside to inside.
I only have two zones setup. inside-trust & outside-untrust
Can I just create one rule to allow skype that lists both zones on either side of the rule?
source | destination | ||||
name | zone | address | zone | address | application |
---|---|---|---|---|---|
rule1 | inside-trust outside-untrust | any | inside-trust outside-untrust | any | skype |
or is it better to have two rules and break it up for inside to outside and outside to inside?
source | destination | ||||
name | zone | address | zone | address | application |
---|---|---|---|---|---|
rule1 | inside-trust | any | outside-untrust | any | skype |
source | destination | ||||
name | zone | address | zone | address | application |
---|---|---|---|---|---|
rule2 | outside-untrust | any | inside-trust | any | skype |
Either way is fine with me, I'm just looking for best practices or if having both zones listed is a bad idea or even supported. Also if anyone has done this and found if it is a good idea or bad idea? Gaming is another example that relates to this question as I work at a university.
Thanks!
10-31-2011 03:12 PM
better to have two rules.helps in troubleshooting...
10-31-2011 05:01 PM
I agree - two rules is much easier to troubleshoot. You can also find yourself shadowing rules quite easily if you combine them. The 'Show Unused Rule' feature is handy to use after a few days as you might fiind some rules you thought were required are completely redundant.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!