<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic A pix port redirection question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486600#M532110</link>
    <description>&lt;P&gt;I have only one public ip address.It was used by outside interface.How can I allow outside host to access to internal&lt;/P&gt;&lt;P&gt;web server?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:27:04 GMT</pubDate>
    <dc:creator>xbw</dc:creator>
    <dc:date>2020-02-21T08:27:04Z</dc:date>
    <item>
      <title>A pix port redirection question</title>
      <link>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486600#M532110</link>
      <description>&lt;P&gt;I have only one public ip address.It was used by outside interface.How can I allow outside host to access to internal&lt;/P&gt;&lt;P&gt;web server?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486600#M532110</guid>
      <dc:creator>xbw</dc:creator>
      <dc:date>2020-02-21T08:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: A pix port redirection question</title>
      <link>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486601#M532111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, you have 2 options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can use that public ip for just the webserver and nothing else then a standard static would do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However if you want to prepare for expansion later, you would need to utilise port forwarding, so you would set it up to forward any port 80 traffic to the privately addressed inside ip address. This is by far the recommended way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See here for details.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094aad.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094aad.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Oct 2005 01:08:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486601#M532111</guid>
      <dc:creator>itchampnz</dc:creator>
      <dc:date>2005-10-09T01:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: A pix port redirection question</title>
      <link>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486602#M532112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;one way is to configure port forwarding on the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp &lt;PIX outside="" int="" ip=""&gt; 80 &lt;WEB server="" private="" ip=""&gt; 80 netmask 255.255.255.255 0 0&lt;/WEB&gt;&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;access-list 100 permit tcp any host &lt;PIX outside="" int="" ip=""&gt; eq 80&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;access-group 100 in interface outside&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the last command "clear xlate" is used to force the pix to refresh the existing address translation, so that the new static statement will be kicked off.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Oct 2005 02:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486602#M532112</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-10-09T02:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: A pix port redirection question</title>
      <link>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486603#M532113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As per Jack Ko's post, you could also use keyword: interface on your static i.e. if you only have one public IP and this IP is being used for the PIX outside interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 80 &lt;WEB server="" private="" ip=""&gt; 80 netmask 255.255.255.255 0 0 &lt;/WEB&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-or-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SMTP access:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 permit tcp any host &lt;PIX outside="" int="" ip=""&gt; eq smtp &lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;access-group 100 in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface smtp &lt;SMTP server="" private="" ip=""&gt; smtp netmask 255.255.255.255 0 0 &lt;/SMTP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, save with: write mem and also issue: clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Oct 2005 09:09:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486603#M532113</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2005-10-09T09:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: A pix port redirection question</title>
      <link>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486604#M532114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've been trying to do a similar port forward, however have been unsuccessful.  My outside address is obtained from my ISP's dhcp and is not static.  This is from a cable modem connection, residential service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to effectively do what standard home retail routers like Linksys or any others do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible over a DHCP'd single address service?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2005 08:56:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-pix-port-redirection-question/m-p/486604#M532114</guid>
      <dc:creator>bobfuller</dc:creator>
      <dc:date>2005-12-01T08:56:45Z</dc:date>
    </item>
  </channel>
</rss>

