<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some problem with PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/some-problem-with-pix/m-p/661217#M496975</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your config looks fine for outbound access.  However, you have a class C on your inside interface, which is 200+ hosts, not even counting anything you may be routing through the pix (the 192.168 class B).  However, your nat/global statements say that only 20 hosts can have outside access (and presumably internet access) at the same time:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;global (outside) 1 61.172.253.99-61.172.253.117 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once 20 internal IP addresses are mapped to 20 external IP addresses, everyone else has to wait until a translation slot frees up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try changing it to the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 61.172.253.99-61.172.253.116&lt;/P&gt;&lt;P&gt;global (outside) 1 61.172.253.117 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means after the first 19 addresses are used by hosts needing translation, everyone else will use PAT - giving you 65000+ more translations for internet access.  However, there are caveats when using PAT for some type of applications, make sure you look them up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out this URL if you have any more questions.  It explains everything you should need to know - assuming nat is your problem.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172786.html#wp1113151" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172786.html#wp1113151&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate if it helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Oct 2006 23:38:33 GMT</pubDate>
    <dc:creator>jgervia_2</dc:creator>
    <dc:date>2006-10-26T23:38:33Z</dc:date>
    <item>
      <title>Some problem with PIX</title>
      <link>https://community.cisco.com/t5/network-security/some-problem-with-pix/m-p/661216#M496974</link>
      <description>&lt;P&gt;I could ping internet website through the PIX(6.3) with internal IP,but only some IP could do this... I check my pix's configuration and find out there are no limits on inside interface(PIX aloow access from high security level interface to low security level interface by default??)..So strange, could some one help me to find the problem??(cut...)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol ils 389&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;names         &lt;/P&gt;&lt;P&gt;access-list 101 permit ip host 192.168.21.100 172.16.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list 102 permit ip host 192.168.1.170 any &lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside *.*.*.* 255.255.255.224&lt;/P&gt;&lt;P&gt;ip address inside 172.18.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;ip local pool normal 172.16.1.1-172.16.1.255&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00&lt;/P&gt;&lt;P&gt;failover poll 15&lt;/P&gt;&lt;P&gt;no failover ip address outside&lt;/P&gt;&lt;P&gt;no failover ip address inside&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 61.172.253.99-61.172.253.117&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 101&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;conduit permit icmp any any &lt;/P&gt;&lt;P&gt;established tcp 135 0 permitto tcp 1024-65535 permitfrom tcp 0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 *.*.*.* 1&lt;/P&gt;&lt;P&gt;route inside 192.168.0.0 255.255.0.0 172.18.1.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;aaa-server partnerauth protocol radius &lt;/P&gt;&lt;P&gt;aaa-server partnerauth (inside) host 192.168.1.43 cisco123 timeout 10&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set myset esp-des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set oss1 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map dynmap 10 set transform-set myset&lt;/P&gt;&lt;P&gt;crypto map mymap 10 ipsec-isakmp dynamic dynmap&lt;/P&gt;&lt;P&gt;crypto map mymap client authentication partnerauth&lt;/P&gt;&lt;P&gt;crypto map mymap interface outside&lt;/P&gt;&lt;P&gt;crypto map transam 10 ipsec-isakmp&lt;/P&gt;&lt;P&gt;crypto map peer1 11 ipsec-isakmp&lt;/P&gt;&lt;P&gt;crypto map peer1 11 set peer 194.39.131.167&lt;/P&gt;&lt;P&gt;crypto map peer1 11 set transform-set oss1&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;/P&gt;&lt;P&gt;isakmp key ******** address 194.39.131.167 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;isakmp identity address&lt;/P&gt;&lt;P&gt;isakmp nat-traversal 30&lt;/P&gt;&lt;P&gt;isakmp policy 10 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 10 encryption des&lt;/P&gt;&lt;P&gt;isakmp policy 10 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 10 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 10 lifetime 86400&lt;/P&gt;&lt;P&gt;vpngroup normal address-pool normal&lt;/P&gt;&lt;P&gt;vpngroup normal dns-server 192.168.1.43 202.96.199.133&lt;/P&gt;&lt;P&gt;vpngroup normal split-tunnel 101&lt;/P&gt;&lt;P&gt;vpngroup normal idle-time 1800&lt;/P&gt;&lt;P&gt;vpngroup normal password ********&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:16:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/some-problem-with-pix/m-p/661216#M496974</guid>
      <dc:creator>sheldon.wu</dc:creator>
      <dc:date>2020-02-21T09:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Some problem with PIX</title>
      <link>https://community.cisco.com/t5/network-security/some-problem-with-pix/m-p/661217#M496975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your config looks fine for outbound access.  However, you have a class C on your inside interface, which is 200+ hosts, not even counting anything you may be routing through the pix (the 192.168 class B).  However, your nat/global statements say that only 20 hosts can have outside access (and presumably internet access) at the same time:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;global (outside) 1 61.172.253.99-61.172.253.117 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once 20 internal IP addresses are mapped to 20 external IP addresses, everyone else has to wait until a translation slot frees up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try changing it to the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 61.172.253.99-61.172.253.116&lt;/P&gt;&lt;P&gt;global (outside) 1 61.172.253.117 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means after the first 19 addresses are used by hosts needing translation, everyone else will use PAT - giving you 65000+ more translations for internet access.  However, there are caveats when using PAT for some type of applications, make sure you look them up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out this URL if you have any more questions.  It explains everything you should need to know - assuming nat is your problem.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172786.html#wp1113151" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172786.html#wp1113151&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate if it helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2006 23:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/some-problem-with-pix/m-p/661217#M496975</guid>
      <dc:creator>jgervia_2</dc:creator>
      <dc:date>2006-10-26T23:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Some problem with PIX</title>
      <link>https://community.cisco.com/t5/network-security/some-problem-with-pix/m-p/661218#M496977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;jgervia,&lt;/P&gt;&lt;P&gt; Thanks a lot. Could you tell me how to free up the translation slot list when the address rangle was exhausted ??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2006 03:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/some-problem-with-pix/m-p/661218#M496977</guid>
      <dc:creator>sheldon.wu</dc:creator>
      <dc:date>2006-10-27T03:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Some problem with PIX</title>
      <link>https://community.cisco.com/t5/network-security/some-problem-with-pix/m-p/661219#M496978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will show you the translation slots.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will clear them, but this is usually disruptive and any connections associated with those translations will go away.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if it's helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2006 19:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/some-problem-with-pix/m-p/661219#M496978</guid>
      <dc:creator>jgervia_2</dc:creator>
      <dc:date>2006-10-27T19:29:15Z</dc:date>
    </item>
  </channel>
</rss>

