<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX 515 case in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-case/m-p/412965#M533961</link>
    <description>&lt;P&gt;i have PIX 515 firewall, i have the following problem:&lt;/P&gt;&lt;P&gt;consider the following:&lt;/P&gt;&lt;P&gt;inside interface: 1.1.1.1/24&lt;/P&gt;&lt;P&gt;DMZ interface: 2.2.2.1/24&lt;/P&gt;&lt;P&gt;outside interface: 3.3.3.1/24&lt;/P&gt;&lt;P&gt;Access-list 10 applied at the inside interface.&lt;/P&gt;&lt;P&gt;access-list 6 applied at the DMZ interface.&lt;/P&gt;&lt;P&gt;Access-list 2 applied at the outside interface.&lt;/P&gt;&lt;P&gt;access-list 10 permit tcp any host 2.2.2.100 eq ftp&lt;/P&gt;&lt;P&gt;for example: &lt;/P&gt;&lt;P&gt;client IP address 1.1.1.100 (inside)&lt;/P&gt;&lt;P&gt;Client IP address 3.3.3.100 (outside)&lt;/P&gt;&lt;P&gt;......&lt;/P&gt;&lt;P&gt;access-list 2 permit tcp any host 2.2.2.100 eq ftp&lt;/P&gt;&lt;P&gt;(ALL Inbound)&lt;/P&gt;&lt;P&gt;Any client from the inside subnet who try to connect through the firewall to FTP Server (2.2.2.100) failed and the windows reason is "FTP Folder error: An error occured opening that folder on the FTP server make sure you have permission to access that folder.&lt;/P&gt;&lt;P&gt;Details:&lt;/P&gt;&lt;P&gt;200 Type set to A.&lt;/P&gt;&lt;P&gt;200 port command successful&lt;/P&gt;&lt;P&gt;425 can't build data connection: connection refused&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;i do the following to solve this problem, i place this entry at the access-list 6 (applied at the DMZ interface inbound)&lt;/P&gt;&lt;P&gt;access-list 6 permit ip host 2.2.2.100 host 1.1.1.100.&lt;/P&gt;&lt;P&gt;and also see these two commands applied:&lt;/P&gt;&lt;P&gt;fixup protocol ftp 20&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;meanwhile the traffic from the outside client can access this DMZ server without any problem and without any permit entry at the DMZ interface like "access-list 6 permit ip host 2.2.2.100 host 3.3.3.100"&lt;/P&gt;&lt;P&gt;Please i need your help!&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:20:51 GMT</pubDate>
    <dc:creator>paltel</dc:creator>
    <dc:date>2020-02-21T08:20:51Z</dc:date>
    <item>
      <title>PIX 515 case</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-case/m-p/412965#M533961</link>
      <description>&lt;P&gt;i have PIX 515 firewall, i have the following problem:&lt;/P&gt;&lt;P&gt;consider the following:&lt;/P&gt;&lt;P&gt;inside interface: 1.1.1.1/24&lt;/P&gt;&lt;P&gt;DMZ interface: 2.2.2.1/24&lt;/P&gt;&lt;P&gt;outside interface: 3.3.3.1/24&lt;/P&gt;&lt;P&gt;Access-list 10 applied at the inside interface.&lt;/P&gt;&lt;P&gt;access-list 6 applied at the DMZ interface.&lt;/P&gt;&lt;P&gt;Access-list 2 applied at the outside interface.&lt;/P&gt;&lt;P&gt;access-list 10 permit tcp any host 2.2.2.100 eq ftp&lt;/P&gt;&lt;P&gt;for example: &lt;/P&gt;&lt;P&gt;client IP address 1.1.1.100 (inside)&lt;/P&gt;&lt;P&gt;Client IP address 3.3.3.100 (outside)&lt;/P&gt;&lt;P&gt;......&lt;/P&gt;&lt;P&gt;access-list 2 permit tcp any host 2.2.2.100 eq ftp&lt;/P&gt;&lt;P&gt;(ALL Inbound)&lt;/P&gt;&lt;P&gt;Any client from the inside subnet who try to connect through the firewall to FTP Server (2.2.2.100) failed and the windows reason is "FTP Folder error: An error occured opening that folder on the FTP server make sure you have permission to access that folder.&lt;/P&gt;&lt;P&gt;Details:&lt;/P&gt;&lt;P&gt;200 Type set to A.&lt;/P&gt;&lt;P&gt;200 port command successful&lt;/P&gt;&lt;P&gt;425 can't build data connection: connection refused&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;i do the following to solve this problem, i place this entry at the access-list 6 (applied at the DMZ interface inbound)&lt;/P&gt;&lt;P&gt;access-list 6 permit ip host 2.2.2.100 host 1.1.1.100.&lt;/P&gt;&lt;P&gt;and also see these two commands applied:&lt;/P&gt;&lt;P&gt;fixup protocol ftp 20&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;meanwhile the traffic from the outside client can access this DMZ server without any problem and without any permit entry at the DMZ interface like "access-list 6 permit ip host 2.2.2.100 host 3.3.3.100"&lt;/P&gt;&lt;P&gt;Please i need your help!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-case/m-p/412965#M533961</guid>
      <dc:creator>paltel</dc:creator>
      <dc:date>2020-02-21T08:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 case</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-case/m-p/412966#M533964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you do Couple of test to confirm your problem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Open the IP stack for the Host.(try Ftp)&lt;/P&gt;&lt;P&gt;2) Can you do ftp within the same segment ( Hope you might have done this).&lt;/P&gt;&lt;P&gt;3) Confirm the NAT for both these interfaces.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Aug 2005 09:28:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-case/m-p/412966#M533964</guid>
      <dc:creator>spvaidya</dc:creator>
      <dc:date>2005-08-29T09:28:23Z</dc:date>
    </item>
  </channel>
</rss>

