<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX, Object-Groups &amp; Port Range Forwarding in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-object-groups-port-range-forwarding/m-p/799714#M1003249</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well the config looks okay. Does the expanded access-list look right when you do a "sh access-list outside_in" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't include the statement but i'm assuming you have applied the access-list to your outside interface ie. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_in in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have applied this then are you sure you have all the ports covered. What if you temporarily allow all IP from one of the remote addresses, does it then work ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Jun 2007 05:57:53 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-06-13T05:57:53Z</dc:date>
    <item>
      <title>PIX, Object-Groups &amp; Port Range Forwarding</title>
      <link>https://community.cisco.com/t5/network-security/pix-object-groups-port-range-forwarding/m-p/799713#M1003248</link>
      <description>&lt;P&gt;Can anyone tell me why the following would not work through a pix 525? I have two remote offices trying to connect back with a VoIP phone system. We are forwarding all traffic on a ouside IP (xxx.xxx.xxx.152) address to an internal IP (xxx.xxx.xxx.12) and defined the following ACL's/Statics.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network Some_NetGroup_1&lt;/P&gt;&lt;P&gt; description Some Remote Offices&lt;/P&gt;&lt;P&gt; network-object xxx.xxx.xxx.14 255.255.255.255&lt;/P&gt;&lt;P&gt; network-object xxx.xxx.xxx.22 255.255.255.255&lt;/P&gt;&lt;P&gt;object-group service Some_Group_TCP tcp&lt;/P&gt;&lt;P&gt; port-object eq xxxx&lt;/P&gt;&lt;P&gt; port-object eq xxxx&lt;/P&gt;&lt;P&gt; port-object eq xxxx&lt;/P&gt;&lt;P&gt;object-group service Some_Group_UDP udp&lt;/P&gt;&lt;P&gt; port-object eq xxxx&lt;/P&gt;&lt;P&gt; port-object range xxxx xxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit tcp object-group Some_NetGroup_1 host xxx.xxx.xxx.152 object-group Some_Group_TCP &lt;/P&gt;&lt;P&gt;access-list outside_in extended permit udp object-group Some_NetGroup_1 host xxx.xxx.xxx.152 object-group Some_Group_UDP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) xxx.xxx.xxx.152 xxx.xxx.xxx.12 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for any suggestions.&lt;/P&gt;&lt;P&gt;Drew&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:28:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-object-groups-port-range-forwarding/m-p/799713#M1003248</guid>
      <dc:creator>dmcintosh</dc:creator>
      <dc:date>2019-03-11T10:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: PIX, Object-Groups &amp; Port Range Forwarding</title>
      <link>https://community.cisco.com/t5/network-security/pix-object-groups-port-range-forwarding/m-p/799714#M1003249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well the config looks okay. Does the expanded access-list look right when you do a "sh access-list outside_in" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't include the statement but i'm assuming you have applied the access-list to your outside interface ie. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_in in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have applied this then are you sure you have all the ports covered. What if you temporarily allow all IP from one of the remote addresses, does it then work ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2007 05:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-object-groups-port-range-forwarding/m-p/799714#M1003249</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-06-13T05:57:53Z</dc:date>
    </item>
  </channel>
</rss>

