<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port Address Redirection- PIX 515e in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477561#M535307</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello koshy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked the configuration and static and access-list looks fine. Please let me know if you have the following command in the configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yes and still the problem persist. Try the following command and test to see if that helps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the problem still occurs. Please send the sh xlate information with the complete configuration file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any questions, please feel free to contact me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;Harish Tandon&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:harishtandon23@gmail.com"&gt;harishtandon23@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 16 Jul 2005 14:42:56 GMT</pubDate>
    <dc:creator>harishtandon23</dc:creator>
    <dc:date>2005-07-16T14:42:56Z</dc:date>
    <item>
      <title>Port Address Redirection- PIX 515e</title>
      <link>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477560#M535306</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am Koshy working with M/s ITI Limited, palakkad. &lt;/P&gt;&lt;P&gt;I have a problem with Port Address Redirection (PIX 515E)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured static translation to a public IP with my internal servers. &lt;/P&gt;&lt;P&gt;Public IP 210.212.235.147 is to be translated to a.b.c.d for "www" packets.&lt;/P&gt;&lt;P&gt;Public IP 210.212.235.147 is to be translated to aa.bb.cc.dd for "smtp and pop3 packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sadly enough requests destined for smtp as well as pop3 doesn't reach inside my network.&lt;/P&gt;&lt;P&gt;Below given is the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not configured NAT &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pixfirewall(config)# sh access-list outside_access_in&lt;/P&gt;&lt;P&gt;access-list outside_access_in; 3 elements&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 1 permit tcp any host 210.212.235.147 eq pop3 (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 2 permit tcp any host 210.212.235.147 eq smtp (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 3 permit tcp any host 210.212.235.147 eq www (hitcnt=4)&lt;/P&gt;&lt;P&gt;pixfirewall(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pixfirewall(config)# sh static&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.147 smtp 10.75.200.3 smtp netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.147 pop3 10.75.200.3 pop3 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.147 www 10.75.200.2 www netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me solve the problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:16:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477560#M535306</guid>
      <dc:creator>koshy</dc:creator>
      <dc:date>2020-02-21T08:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: Port Address Redirection- PIX 515e</title>
      <link>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477561#M535307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello koshy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked the configuration and static and access-list looks fine. Please let me know if you have the following command in the configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yes and still the problem persist. Try the following command and test to see if that helps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the problem still occurs. Please send the sh xlate information with the complete configuration file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any questions, please feel free to contact me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;Harish Tandon&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:harishtandon23@gmail.com"&gt;harishtandon23@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Jul 2005 14:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477561#M535307</guid>
      <dc:creator>harishtandon23</dc:creator>
      <dc:date>2005-07-16T14:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Port Address Redirection- PIX 515e</title>
      <link>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477562#M535309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Harish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below given is the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pixfirewall(config)# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;PIX Version 6.3(4)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host 210.212.235.147 eq www&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host 210.212.235.148 eq smtp&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host 210.212.235.148 eq pop3&lt;/P&gt;&lt;P&gt;pager lines 1000&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside 210.212.235.146 255.255.255.248&lt;/P&gt;&lt;P&gt;ip address inside 10.75.200.1 255.255.0.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm logging informational 100&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.147 www 10.75.200.2 www netmask 255.255.&lt;/P&gt;&lt;P&gt;255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.147 smtp 10.75.200.3 smtp netmask 255.25&lt;/P&gt;&lt;P&gt;5.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 210.212.235.148 10.75.200.3 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;access-group acl-in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 210.212.235.145 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 10.75.200.11 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet 10.75.200.2 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;telnet 10.75.200.11 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd lease 3600&lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 750&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;pixfirewall(config)#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 08:47:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477562#M535309</guid>
      <dc:creator>koshy</dc:creator>
      <dc:date>2005-07-19T08:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Port Address Redirection- PIX 515e</title>
      <link>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477563#M535311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just connected to your public IPs i.e.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;210.212.235.147 connected to port 80 (www), 210.212.235.148 connected to port 110 (pop3),&lt;/P&gt;&lt;P&gt;210.212.235.148 connected to port 25 (smtp)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, your outside ACL should be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host 210.212.235.147 eq www &lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host 210.212.235.148 eq smtp &lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host 210.212.235.148 eq pop3 &lt;/P&gt;&lt;P&gt;access-group acl-in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your static should be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.148 smtp 10.75.200.3 smtp netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.148 pop3 10.75.200.3 pop3 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.147 www 10.75.200.2 www netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now save with: write mem and also isssue: clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps and please rate post if it does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 10:28:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477563#M535311</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2005-07-19T10:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Port Address Redirection- PIX 515e</title>
      <link>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477564#M535314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, again..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also notice that your public IP 210.212.235.148 answers to telnet on port 80, so, is your inside www server IP = 10.75.200.3 (Public IP: 210.212.235.148) OR is it 10.75.200.2 (Public IP 210.212.235.147)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which IP is it???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 10:38:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477564#M535314</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2005-07-19T10:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Port Address Redirection- PIX 515e</title>
      <link>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477565#M535317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello JMIA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There was some errors in the cofig I sent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration I need to work is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host 210.212.235.147 eq www &lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host 210.212.235.147 eq smtp &lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host 210.212.235.147 eq pop3 &lt;/P&gt;&lt;P&gt;access-group acl-in in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.147 www 10.75.200.2 www netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.147 smtp 10.75.200.3 smtp netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 210.212.235.147 pop3 10.75.200.3 pop3 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry 4 the error. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2005 05:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-address-redirection-pix-515e/m-p/477565#M535317</guid>
      <dc:creator>koshy</dc:creator>
      <dc:date>2005-07-20T05:35:08Z</dc:date>
    </item>
  </channel>
</rss>

