default, static routes, access-list in Security lab

From: John Moor (johmoor@gmail.com)
Date: Tue Oct 24 2006 - 05:33:12 ART


Guys could you please tell me... Well we all know that it is written in the
real lab that default and static routes could be set only if it is written
in the task.. correct?? But the following things I am not sure about:

1) What could I use in the outside access-list of the PIX???
a) Could I just type access-list OUTSIDE permit ip any any... (It seems this
is not prohibited... but funny though).

b) Can I use access-list OUTSIDE permit icmp any any if it is not written in
the task?? (I have seen this in one of the workbooks...)

c) Can I use access-list OUTSIDE permit esp any any instead of access-lsit
OUTSIDE permit esp host 1.1.1.1 host 2.2.2.2. If ipsec is needed between
only two points??

2. VPN3K.
a) Can I set the tunnel default gateway parameter.. if it is written to set
only default gateway parameter on the concentrator??

b) I can't also use static routes on the vPN3K if it is not told in the
task? Or those rules are only for routers and switches??

Thank you very much for any clarifications..



This archive was generated by hypermail 2.1.4 : Wed Nov 01 2006 - 07:29:06 ART