<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 501 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-501/m-p/476529#M532308</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from you last post:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 6.1.5.ext host ext.ext.ext.2 eq smtp&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host ext.ext.ext.3 eq https&lt;/P&gt;&lt;P&gt;access-list nonat permit ip 172.16.0.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address outside ext.ext.ext.1 subnet.subnet.subnet.subnet&lt;/P&gt;&lt;P&gt;ip address inside 172.16.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;ip local pool uk 192.168.1.1-192.168.1.100&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp ext.ext.ext.2 25 172.16.0.10 25 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp ext.ext.ext.2 443 172.16.0.11 443 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 ext.ext.ext.4 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host ext.ext.ext.3 eq https&lt;/P&gt;&lt;P&gt;should be&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host ext.ext.ext.2 eq https &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Oct 2005 12:42:25 GMT</pubDate>
    <dc:creator>jackko</dc:creator>
    <dc:date>2005-10-06T12:42:25Z</dc:date>
    <item>
      <title>PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/pix-501/m-p/476524#M532292</link>
      <description>&lt;P&gt;I need some help configuring SSL packets forwarded to a webserver. The problem is that the pix is live and is already forwarding SMTP to mail. but we need to use the same ip which the mail server utilizes for SSL web.&lt;/P&gt;&lt;P&gt;The xternal pool available is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ext.ext.ext.1 ( outside ip )&lt;/P&gt;&lt;P&gt;ext.ext.ext.2 ( want to use SMTP and SSL)&lt;/P&gt;&lt;P&gt;ext.ext.ext.3 ( Should not be used )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;internal range&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;172.16.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*********************************&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 6.1.5.ext host ext.ext.ext.2 eq smtp&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host ext.ext.ext.3 eq https&lt;/P&gt;&lt;P&gt;access-list nonat permit ip 172.16.0.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address outside ext.ext.ext.1 subnet.subnet.subnet.subnet&lt;/P&gt;&lt;P&gt;ip address inside 172.16.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;ip local pool uk 192.168.1.1-192.168.1.100&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) ext.ext.ext.2 172.16.0.10 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) ext.ext.ext.3 172.16.0.11 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 ext.ext.ext.4 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501/m-p/476524#M532292</guid>
      <dc:creator>ramesys12</dc:creator>
      <dc:date>2020-02-21T08:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/pix-501/m-p/476525#M532296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to clarify further We want to use&lt;/P&gt;&lt;P&gt;ext.ext.ext.2 ( want to use SMTP and SSL) to forward ext.ext.ext.2 smtp to 172.16.0.10 &lt;/P&gt;&lt;P&gt;ext.ext.ext.2 SSL to 172.16.0.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;usign the same external ip I am not sure hwo I should change the config without breaking anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note : I have been asked not use the ext.ext.ext.3 ( Should not be used ) so this command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host ext.ext.ext.3 eq https &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will need to be removed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2005 10:29:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501/m-p/476525#M532296</guid>
      <dc:creator>ramesys12</dc:creator>
      <dc:date>2005-10-06T10:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/pix-501/m-p/476526#M532299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no static (inside,outside) ext.ext.ext.2 172.16.0.10 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp ext.ext.ext.2 25 172.16.0.10 25 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp ext.ext.ext.2 443 172.16.0.11 443 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any ext.ext.ext.2 eq 25&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any ext.ext.ext.2 eq 443&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need to fresh the ip address translation i.e. "clear xlate". it will drop all the existing connections, however, it will reconnect straight away. unfortunately this few seconds interruption is not aviodable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2005 11:09:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501/m-p/476526#M532299</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-10-06T11:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/pix-501/m-p/476527#M532302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list 101 permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 6.1.5.ext host ext.ext.ext.2 eq smtp &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host ext.ext.ext.3 eq https &lt;/P&gt;&lt;P&gt;access-list nonat permit ip 172.16.0.0 255.255.255.0 192.168.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip address outside ext.ext.ext.1 subnet.subnet.subnet.subnet &lt;/P&gt;&lt;P&gt;ip address inside 172.16.0.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip audit info action alarm &lt;/P&gt;&lt;P&gt;ip audit attack action alarm &lt;/P&gt;&lt;P&gt;ip local pool uk 192.168.1.1-192.168.1.100 &lt;/P&gt;&lt;P&gt;arp timeout 14400 &lt;/P&gt;&lt;P&gt;global (outside) 1 interface &lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp ext.ext.ext.2 25 172.16.0.10 25 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp ext.ext.ext.2 443 172.16.0.11 443 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group 101 in interface outside &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 ext.ext.ext.4 1 &lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00 &lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00 &lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00 &lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute &lt;/P&gt;&lt;P&gt;floodguard enable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 inside &lt;/P&gt;&lt;P&gt;telnet timeout 5 &lt;/P&gt;&lt;P&gt;console timeout 0 &lt;/P&gt;&lt;P&gt;terminal width 80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access-list is a bit different as they receive emails from only one server (ISP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the above config looks ok does it if any of the lines go missing while I am doing this that means something has gone wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I did try making a simialr config change yesterday and all internal traffic stopped going out...so simply taking a clear picture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To get that to work last night I had to add these two lines back again manually &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;not sure why they disappeared&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2005 11:31:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501/m-p/476527#M532302</guid>
      <dc:creator>ramesys12</dc:creator>
      <dc:date>2005-10-06T11:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/pix-501/m-p/476528#M532306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it's fine if you are going to restrict the smtp access from the isp only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;without the command "nat (inside) 1 0.0.0.0 0.0.0.0 0 0 ", no internal user will be able to access the internet  since the pix will not perform pat anymore.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2005 12:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501/m-p/476528#M532306</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-10-06T12:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/pix-501/m-p/476529#M532308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from you last post:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 6.1.5.ext host ext.ext.ext.2 eq smtp&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host ext.ext.ext.3 eq https&lt;/P&gt;&lt;P&gt;access-list nonat permit ip 172.16.0.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address outside ext.ext.ext.1 subnet.subnet.subnet.subnet&lt;/P&gt;&lt;P&gt;ip address inside 172.16.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;ip local pool uk 192.168.1.1-192.168.1.100&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp ext.ext.ext.2 25 172.16.0.10 25 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp ext.ext.ext.2 443 172.16.0.11 443 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 ext.ext.ext.4 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host ext.ext.ext.3 eq https&lt;/P&gt;&lt;P&gt;should be&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host ext.ext.ext.2 eq https &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2005 12:42:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501/m-p/476529#M532308</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-10-06T12:42:25Z</dc:date>
    </item>
  </channel>
</rss>

