Access-list 101 permit ip host so.ur.ce.ip host dest.inat.ion.ip (public adrress of inside host via NAT, unless your doing NAT0 on the specific host)
... then, apply it to the outside interface. Someone correct me if I'm wrong. Mark -----Original Message----- From: JohnZ [mailto:[EMAIL PROTECTED]] Sent: Tuesday, September 17, 2002 5:52 PM To: [EMAIL PROTECTED] Subject: PIX Access-list host to host [7:53515] Hi, Can some one tell me if it's possible to give full access host to host without specifing a port. Basically what I would like to do is open up temporarily complete access between a host on the outside and one on the inside. I have searched the CCO and havn't found any thing that tells me it's possible. Thanks, Shawn Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=53523&t=53515 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]