<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic  Thanks Marvin &amp; nkarthikeyan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix501/m-p/2500304#M237527</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Marvin &amp;amp; nkarthikeyan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;response below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pix501# sh xlate&lt;BR /&gt;1 in use, 1 most used&lt;BR /&gt;Global 192.168.1.250 Local 192.168.10.9&lt;/P&gt;&lt;P&gt;------------------------------------&lt;/P&gt;&lt;P&gt;pix501# ping 4.2.2.2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;4.2.2.2 NO response received -- 1000ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;4.2.2.2 NO response received -- 1000ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;4.2.2.2 NO response received -- 1000ms&lt;BR /&gt;pix501# ping 192.168.1.254&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.1.254 response received -- 0ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.1.254 response received -- 0ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.1.254 response received -- 0ms&lt;BR /&gt;pix501# ping 192.168.10.254&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.10.254 response received -- 0ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.10.254 response received -- 0ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.10.254 response received -- 0ms&lt;/P&gt;&lt;P&gt;---------------------------&lt;/P&gt;&lt;P&gt;pix501# sh run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;PIX Version 6.3(5)&lt;BR /&gt;interface ethernet0 auto&lt;BR /&gt;interface ethernet1 100full&lt;BR /&gt;nameif ethernet0 outside security0&lt;BR /&gt;nameif ethernet1 inside security100&lt;BR /&gt;enable password Oh/B06WiVgeUmuvX encrypted&lt;BR /&gt;passwd Oh/B06WiVgeUmuvX encrypted&lt;BR /&gt;hostname pix501&lt;BR /&gt;domain-name ceci.ct&lt;BR /&gt;fixup protocol dns maximum-length 512&lt;BR /&gt;fixup protocol ftp 21&lt;BR /&gt;fixup protocol h323 h225 1720&lt;BR /&gt;fixup protocol h323 ras 1718-1719&lt;BR /&gt;fixup protocol http 80&lt;BR /&gt;fixup protocol rsh 514&lt;BR /&gt;fixup protocol rtsp 554&lt;BR /&gt;fixup protocol sip 5060&lt;BR /&gt;fixup protocol sip udp 5060&lt;BR /&gt;fixup protocol skinny 2000&lt;BR /&gt;fixup protocol smtp 25&lt;BR /&gt;fixup protocol sqlnet 1521&lt;BR /&gt;fixup protocol tftp 69&lt;BR /&gt;names &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;ip address outside 192.168.1.254 255.255.255.0&lt;BR /&gt;ip address inside 192.168.10.254 255.255.255.0&lt;BR /&gt;ip audit info action alarm&lt;BR /&gt;ip audit attack action alarm&lt;BR /&gt;pdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 192.168.1.250-192.168.1.253 netmask 255.255.255.0&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;BR /&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;BR /&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;BR /&gt;timeout uauth 0:05:00 absolute&lt;BR /&gt;aaa-server TACACS+ protocol tacacs+&amp;nbsp;&lt;BR /&gt;aaa-server TACACS+ max-failed-attempts 3&amp;nbsp;&lt;BR /&gt;aaa-server TACACS+ deadtime 10&amp;nbsp;&lt;BR /&gt;aaa-server RADIUS protocol radius&amp;nbsp;&lt;BR /&gt;aaa-server RADIUS max-failed-attempts 3&amp;nbsp;&lt;BR /&gt;aaa-server RADIUS deadtime 10&amp;nbsp;&lt;BR /&gt;aaa-server LOCAL protocol local&amp;nbsp;&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.10.0 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server community public&lt;BR /&gt;no snmp-server enable traps&lt;BR /&gt;floodguard enable&lt;BR /&gt;telnet 192.168.10.0 255.255.255.0 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;username ceci password 5CwZJAdZ4FVqqjJR encrypted privilege 2&lt;BR /&gt;terminal width 80&lt;BR /&gt;Cryptochecksum:2c6954d2214415aff5a758c1ece29dc5&lt;BR /&gt;: end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jun 2014 18:24:04 GMT</pubDate>
    <dc:creator>ciscoceci</dc:creator>
    <dc:date>2014-06-17T18:24:04Z</dc:date>
    <item>
      <title>PIX501</title>
      <link>https://community.cisco.com/t5/network-security/pix501/m-p/2500299#M237522</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have conected a pix to adsl router cisco (ppp chap) with this parameters:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pix:&lt;/P&gt;&lt;P&gt;inside: 192.168.10.xx (LAN)&lt;/P&gt;&lt;P&gt;outside 192.168.1.xx (Managment IP router connected to ADSL)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How i can configure pix to get www from lan pc??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Anna&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:20:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix501/m-p/2500299#M237522</guid>
      <dc:creator>ciscoceci</dc:creator>
      <dc:date>2019-03-12T04:20:08Z</dc:date>
    </item>
    <item>
      <title>Hi Anna,</title>
      <link>https://community.cisco.com/t5/network-security/pix501/m-p/2500300#M237523</link>
      <description>&lt;P&gt;Hi Anna,&lt;/P&gt;
&lt;P&gt;Make sure you configure interface with IP address properly, name it &amp;amp; assign a security level ( 100 for inside &amp;amp; 0 for outside). After that do nat/pat for the internet access. There you get the internet access for your LAN PC.&lt;/P&gt;

&lt;PRE&gt;
global (outside) 1 interface
nat (inside) 1 192.168.10.0 255.255.255.0 0 0&lt;/PRE&gt;

&lt;P&gt;Hope this helps&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Karthik&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2014 09:55:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix501/m-p/2500300#M237523</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-06-16T09:55:24Z</dc:date>
    </item>
    <item>
      <title>Thanks nkarthikeyan, I</title>
      <link>https://community.cisco.com/t5/network-security/pix501/m-p/2500301#M237524</link>
      <description>&lt;P&gt;Thanks nkarthikeyan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configure as follow below but i don´t have access from a PC with IP 192.168.10.9/24 gw: 192.168.10.254&lt;/P&gt;&lt;P&gt;Could i have any mistake?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks Anna.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;ip address outside 192.168.1.254 255.255.255.0&lt;BR /&gt;ip address inside 192.168.10.254 255.255.255.0&lt;BR /&gt;ip audit info action alarm&lt;BR /&gt;ip audit attack action alarm&lt;BR /&gt;pdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 192.168.1.250-192.168.1.253 netmask 255.255.255.0&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2014 21:06:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix501/m-p/2500301#M237524</guid>
      <dc:creator>ciscoceci</dc:creator>
      <dc:date>2014-06-16T21:06:53Z</dc:date>
    </item>
    <item>
      <title>The subset of your</title>
      <link>https://community.cisco.com/t5/network-security/pix501/m-p/2500302#M237525</link>
      <description>&lt;P&gt;The subset of your configuration that you shared looks OK.&lt;/P&gt;&lt;P&gt;While trying to access the outside, can you get the output of "show xlate" on the Pix?&lt;/P&gt;&lt;P&gt;The upstream router will also be needing to do its own NAT from the 192.168.1.0/24 addresses to something publicly routable.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2014 22:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix501/m-p/2500302#M237525</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-06-16T22:11:00Z</dc:date>
    </item>
    <item>
      <title>Hi Anna, R u able to reach</title>
      <link>https://community.cisco.com/t5/network-security/pix501/m-p/2500303#M237526</link>
      <description>&lt;P&gt;Hi Anna,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R u able to reach internet from firewall.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;are you able to ping from FW to 4.2.2.2? or any internet sites??&lt;/LI&gt;&lt;LI&gt;are u able to ping the gateway address from firewall?&lt;/LI&gt;&lt;LI&gt;do you have any access-list on the assigned interfaces?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If possible can you provide the complete FW configuration after checking the above things.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 16:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix501/m-p/2500303#M237526</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-06-17T16:57:51Z</dc:date>
    </item>
    <item>
      <title> Thanks Marvin &amp; nkarthikeyan</title>
      <link>https://community.cisco.com/t5/network-security/pix501/m-p/2500304#M237527</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Marvin &amp;amp; nkarthikeyan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;response below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pix501# sh xlate&lt;BR /&gt;1 in use, 1 most used&lt;BR /&gt;Global 192.168.1.250 Local 192.168.10.9&lt;/P&gt;&lt;P&gt;------------------------------------&lt;/P&gt;&lt;P&gt;pix501# ping 4.2.2.2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;4.2.2.2 NO response received -- 1000ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;4.2.2.2 NO response received -- 1000ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;4.2.2.2 NO response received -- 1000ms&lt;BR /&gt;pix501# ping 192.168.1.254&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.1.254 response received -- 0ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.1.254 response received -- 0ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.1.254 response received -- 0ms&lt;BR /&gt;pix501# ping 192.168.10.254&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.10.254 response received -- 0ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.10.254 response received -- 0ms&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.10.254 response received -- 0ms&lt;/P&gt;&lt;P&gt;---------------------------&lt;/P&gt;&lt;P&gt;pix501# sh run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;PIX Version 6.3(5)&lt;BR /&gt;interface ethernet0 auto&lt;BR /&gt;interface ethernet1 100full&lt;BR /&gt;nameif ethernet0 outside security0&lt;BR /&gt;nameif ethernet1 inside security100&lt;BR /&gt;enable password Oh/B06WiVgeUmuvX encrypted&lt;BR /&gt;passwd Oh/B06WiVgeUmuvX encrypted&lt;BR /&gt;hostname pix501&lt;BR /&gt;domain-name ceci.ct&lt;BR /&gt;fixup protocol dns maximum-length 512&lt;BR /&gt;fixup protocol ftp 21&lt;BR /&gt;fixup protocol h323 h225 1720&lt;BR /&gt;fixup protocol h323 ras 1718-1719&lt;BR /&gt;fixup protocol http 80&lt;BR /&gt;fixup protocol rsh 514&lt;BR /&gt;fixup protocol rtsp 554&lt;BR /&gt;fixup protocol sip 5060&lt;BR /&gt;fixup protocol sip udp 5060&lt;BR /&gt;fixup protocol skinny 2000&lt;BR /&gt;fixup protocol smtp 25&lt;BR /&gt;fixup protocol sqlnet 1521&lt;BR /&gt;fixup protocol tftp 69&lt;BR /&gt;names &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;ip address outside 192.168.1.254 255.255.255.0&lt;BR /&gt;ip address inside 192.168.10.254 255.255.255.0&lt;BR /&gt;ip audit info action alarm&lt;BR /&gt;ip audit attack action alarm&lt;BR /&gt;pdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 192.168.1.250-192.168.1.253 netmask 255.255.255.0&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;BR /&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;BR /&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;BR /&gt;timeout uauth 0:05:00 absolute&lt;BR /&gt;aaa-server TACACS+ protocol tacacs+&amp;nbsp;&lt;BR /&gt;aaa-server TACACS+ max-failed-attempts 3&amp;nbsp;&lt;BR /&gt;aaa-server TACACS+ deadtime 10&amp;nbsp;&lt;BR /&gt;aaa-server RADIUS protocol radius&amp;nbsp;&lt;BR /&gt;aaa-server RADIUS max-failed-attempts 3&amp;nbsp;&lt;BR /&gt;aaa-server RADIUS deadtime 10&amp;nbsp;&lt;BR /&gt;aaa-server LOCAL protocol local&amp;nbsp;&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.10.0 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server community public&lt;BR /&gt;no snmp-server enable traps&lt;BR /&gt;floodguard enable&lt;BR /&gt;telnet 192.168.10.0 255.255.255.0 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;username ceci password 5CwZJAdZ4FVqqjJR encrypted privilege 2&lt;BR /&gt;terminal width 80&lt;BR /&gt;Cryptochecksum:2c6954d2214415aff5a758c1ece29dc5&lt;BR /&gt;: end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 18:24:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix501/m-p/2500304#M237527</guid>
      <dc:creator>ciscoceci</dc:creator>
      <dc:date>2014-06-17T18:24:04Z</dc:date>
    </item>
    <item>
      <title>Hi Anna, I guess you have</title>
      <link>https://community.cisco.com/t5/network-security/pix501/m-p/2500305#M237528</link>
      <description>&lt;P&gt;Hi Anna,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess you have some problem with the internet connection over there. Do you ahave any option to check directly connect your PC to the model/router and check the internet access.&lt;/P&gt;&lt;P&gt;Also try to ping 192.168.1.1 from firewall and from PC which is the ADSL router assigned IP. So that we can isolate whether the problem with internet or pix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 18:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix501/m-p/2500305#M237528</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-06-17T18:35:49Z</dc:date>
    </item>
    <item>
      <title>So we see you can reach your</title>
      <link>https://community.cisco.com/t5/network-security/pix501/m-p/2500306#M237529</link>
      <description>&lt;P&gt;So we see you can reach your default gateway for outside routes and that your NAT is building XLATE entries. That (plus reviewing your config) all indicates your Pix configuration is setup properly.&lt;/P&gt;&lt;P&gt;As I noted earlier "&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;The upstream router will also be needing to do its own NAT from the 192.168.1.0/24 addresses to something publicly routable.&lt;/SPAN&gt;" I would investigate that device for its NAT setup and operation as it appears to be the issue in this case.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 18:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix501/m-p/2500306#M237529</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-06-17T18:37:47Z</dc:date>
    </item>
  </channel>
</rss>

