Re: PIX 6.3 - capture command



Walter Roberson wrote:
In article <ddnicb$74v$1@xxxxxxxxxxxxxxx>,
Amaury Ronflard  <amaury99@xxxxxxxxxxxxxxx> wrote:
:I have two PIX


and, an access-list to bound to what to encrypt to get to pix-b


access-list to-pix-b permit tcp 192.168.10.0 255.255.255.128 192.168.20.0 255.255.255.128 eq 5222
access-list to-pix-b permit tcp 192.168.20.0 255.255.255.128 192.168.10.0 255.255.255.128
access-list to-pix-b permit icmp 192.168.10.0 255.255.255.128 192.168.20.0 255.255.255.128 eq 5222
access-list to-pix-b permit icmp 192.168.20.0 255.255.255.128 192.168.10.0 255.255.255.128


The third and fourth lines duplicate the first and second.

Actually, the third line doesn't make sense... "eq" is not a valid keyword with ICMP, and there's no such thing as an ICMP type 5222 packet.



-- Francois Labreque | The surest sign of the existence of extra- flabreque | terrestrial intelligence is that they never @ | bothered to come down here and visit us! videotron.ca | - Calvin .