<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic pix acl question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-acl-question/m-p/605220#M499108</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;im a newbie to using a pix firewall and i have inherited a 525 and would like someone to help point me in the right direction for what my company wants. We have a webserver in our dmz that now needs to communicate with microsofts active directory protocols that are on the inside interface. I have the ports that need to be used but I must confess I'm a bit stuck with where to go now. &lt;/P&gt;&lt;P&gt;Is it simply a matter of creating a new acl from the dmz --&amp;gt; inside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Help would be great. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 09:04:03 GMT</pubDate>
    <dc:creator>miketumolo</dc:creator>
    <dc:date>2020-02-21T09:04:03Z</dc:date>
    <item>
      <title>pix acl question</title>
      <link>https://community.cisco.com/t5/network-security/pix-acl-question/m-p/605220#M499108</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;im a newbie to using a pix firewall and i have inherited a 525 and would like someone to help point me in the right direction for what my company wants. We have a webserver in our dmz that now needs to communicate with microsofts active directory protocols that are on the inside interface. I have the ports that need to be used but I must confess I'm a bit stuck with where to go now. &lt;/P&gt;&lt;P&gt;Is it simply a matter of creating a new acl from the dmz --&amp;gt; inside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Help would be great. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-acl-question/m-p/605220#M499108</guid>
      <dc:creator>miketumolo</dc:creator>
      <dc:date>2020-02-21T09:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: pix acl question</title>
      <link>https://community.cisco.com/t5/network-security/pix-acl-question/m-p/605221#M499110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello miketumolo, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct.  The acl that is created will be on the dmz interface.  As that traffic is permitted, the return traffic will be allowed back via the ASA so you don't have to do anything on the inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what the ACLs elements will look like.&lt;/P&gt;&lt;P&gt;access-list dmz_acl permit tcp host webserver host ADserver eq portnumber&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group dmz_acl in interface dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!  If so, please rate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jul 2006 17:56:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-acl-question/m-p/605221#M499110</guid>
      <dc:creator>hemendoz</dc:creator>
      <dc:date>2006-07-24T17:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: pix acl question</title>
      <link>https://community.cisco.com/t5/network-security/pix-acl-question/m-p/605222#M499112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Be aware, because you are going from a lower security interface (DMZ) to a higher security interface (inside) you also need a static next to the ACL.&lt;/P&gt;&lt;P&gt;If you want to make the AD server available without NAT on the DMZ, use;&lt;/P&gt;&lt;P&gt;static (inside,dmz) &lt;IP address="" internal="" server=""&gt; &lt;SAME ip="" address="" internal="" server="" netmask="" mask=""&gt;&lt;/SAME&gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to nat the AD server, use;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) &lt;RESERVED ip="" address="" on="" dmz=""&gt; &lt;IP address="" internal="" server="" netmask="" mask=""&gt;&lt;/IP&gt;&lt;/RESERVED&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2006 06:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-acl-question/m-p/605222#M499112</guid>
      <dc:creator>koksm</dc:creator>
      <dc:date>2006-07-25T06:36:39Z</dc:date>
    </item>
  </channel>
</rss>

