<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't get port 80 forwarding working on 515E in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621651#M1023744</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't get port forwarding working into a PIX515E. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what I have done and port 80 doesn't open. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name 203.144.238.79 WEBSVR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (PublicDMZ,outside) 203.144.238.79 192.168.10.17 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list PublicDMZ_access_in permit tcp host 192.168.10.17 any eq http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 192.168.10.17 eq http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can telnet to the DMZ addresses on port 80 from the src of the internal Pix range from an upstream router.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Am I forgeting something. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:43:36 GMT</pubDate>
    <dc:creator>cameronjohn</dc:creator>
    <dc:date>2019-03-11T09:43:36Z</dc:date>
    <item>
      <title>Can't get port 80 forwarding working on 515E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621651#M1023744</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't get port forwarding working into a PIX515E. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what I have done and port 80 doesn't open. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name 203.144.238.79 WEBSVR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (PublicDMZ,outside) 203.144.238.79 192.168.10.17 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list PublicDMZ_access_in permit tcp host 192.168.10.17 any eq http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 192.168.10.17 eq http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can telnet to the DMZ addresses on port 80 from the src of the internal Pix range from an upstream router.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Am I forgeting something. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621651#M1023744</guid>
      <dc:creator>cameronjohn</dc:creator>
      <dc:date>2019-03-11T09:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get port 80 forwarding working on 515E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621652#M1023747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please put in the following commands,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list outside_access_in permit tcp any host 192.168.10.17 eq http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 203.144.238.79 eq http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cl xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the outside,the traffic will come with dest. ip address as the public ip .In the existing access-list it's the private ip address,that's why it's not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;plz do the changes and let us know if it work or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sushil&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 14:46:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621652#M1023747</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2007-03-08T14:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get port 80 forwarding working on 515E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621653#M1023751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dont forget to apply the acl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 14:51:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621653#M1023751</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-08T14:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get port 80 forwarding working on 515E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621654#M1023753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 14:53:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621654#M1023753</guid>
      <dc:creator>cameronjohn</dc:creator>
      <dc:date>2007-03-08T14:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get port 80 forwarding working on 515E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621655#M1023754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I Tried what was suggested before and I have done the follwoing and it still isn't working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name 203.144.238.79 WEBSVR &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no static (PublicDMZ,outside) 203.144.238.79 192.168.10.17 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (PublicDMZ,outside)tcp 203.144.238.79 www 192.168.10.17 www netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 203.144.238.79 eq http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is any entry in the sh xlate table as &lt;/P&gt;&lt;P&gt;Global WEBSVR Local 192.168.10.17&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to route the public range via the outside interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 15:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621655#M1023754</guid>
      <dc:creator>cameronjohn</dc:creator>
      <dc:date>2007-03-08T15:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get port 80 forwarding working on 515E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621656#M1023755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is 203.144.238.79 also your outside interface address?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 15:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621656#M1023755</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-08T15:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get port 80 forwarding working on 515E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621657#M1023756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ip address 203.144.238.70 255.255.255.0 is my WAN IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 21:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621657#M1023756</guid>
      <dc:creator>cameronjohn</dc:creator>
      <dc:date>2007-03-08T21:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get port 80 forwarding working on 515E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621658#M1023758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's unclear how your network is setup. Is your setup something like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet --- Router --- PIX --- PublicDMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the WAN IP on the outside router is 203.144.238.70 then does it know how to route to 203.144.238.79. If it doesn't then you can add a static host route, /32 bit mask, to forward the traffic to the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the setup is different or I misunderstood any part of your configuration then clarify that and posting the configuration would help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 22:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621658#M1023758</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2007-03-08T22:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get port 80 forwarding working on 515E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621659#M1023760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you still have an access-group applied on the  PublicDMZ interface ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove it and then try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it works, then add the following entry in the ACL :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list PublicDMZ_access_in permit tcp host 192.168.10.17 eq 80 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then reapply the access-grup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Please rate if it helped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kanishka&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 23:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621659#M1023760</guid>
      <dc:creator>kaachary</dc:creator>
      <dc:date>2007-03-08T23:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get port 80 forwarding working on 515E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621660#M1023762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is all fixed now. Thanks for all your replies. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (PublicDMZ,outside) tcp 203.144.238.79 http 192.168.10.16 http netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;access-list PublicDMZ_access_in permit tcp host 192.168.10.16 any eq http&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 203.144.238.79 eq http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 203.144.238.79 255.255.255.224 203.144.238.68 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 203.144.238.68 being the upstream router back to our network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2007 11:25:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-port-80-forwarding-working-on-515e/m-p/621660#M1023762</guid>
      <dc:creator>cameronjohn</dc:creator>
      <dc:date>2007-03-09T11:25:44Z</dc:date>
    </item>
  </channel>
</rss>

