<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco PIX 515E Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353209#M549117</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help, here is my pix config.&lt;/P&gt;&lt;P&gt;===============================================&lt;/P&gt;&lt;P&gt;PIX Version 6.3(4)                  &lt;/P&gt;&lt;P&gt;interface ethernet0 auto shutdown                                 &lt;/P&gt;&lt;P&gt;interface ethernet1 auto shutdown                                 &lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0                                  &lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100                                   &lt;/P&gt;&lt;P&gt;enable password xxxx encrypted                                          &lt;/P&gt;&lt;P&gt;passwd xxxx&lt;/P&gt;&lt;P&gt;encrypted                                 &lt;/P&gt;&lt;P&gt;hostname pixfirewall                    &lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512                                     &lt;/P&gt;&lt;P&gt;fixup protocol ftp 21                     &lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720                             &lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719                                 &lt;/P&gt;&lt;P&gt;fixup protocol http 80                      &lt;/P&gt;&lt;P&gt;fixup protocol rsh 514                      &lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554                       &lt;/P&gt;&lt;P&gt;fixup protocol sip 5060                       &lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060                           &lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000                          &lt;/P&gt;&lt;P&gt;fixup protocol smtp 25                      &lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521                          &lt;/P&gt;&lt;P&gt;fixup protocol tftp 69                      &lt;/P&gt;&lt;P&gt;names     &lt;/P&gt;&lt;P&gt;pager lines 24              &lt;/P&gt;&lt;P&gt;mtu outside 1500                &lt;/P&gt;&lt;P&gt;mtu inside 1500               &lt;/P&gt;&lt;P&gt;ip address outside x.x.x.yyy xxx.xxx.xxx.xxx                                                 &lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.254 255.255.255.0                                             &lt;/P&gt;&lt;P&gt;ip audit info action alarm                          &lt;/P&gt;&lt;P&gt;ip audit attack action alarm                            &lt;/P&gt;&lt;P&gt;no failover           &lt;/P&gt;&lt;P&gt;failover timeout 0:00:00                        &lt;/P&gt;&lt;P&gt;failover poll 15                &lt;/P&gt;&lt;P&gt;no failover ip address outside                              &lt;/P&gt;&lt;P&gt;no failover ip address inside                             &lt;/P&gt;&lt;P&gt;pdm history enable                  &lt;/P&gt;&lt;P&gt;arp timeout 14400                 &lt;/P&gt;&lt;P&gt;timeout xlate           &lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.5 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;===============================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, I got only one registerd ip address and now  already assigned to the outside interface of my pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Sothearith Chanty.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Apr 2005 01:29:14 GMT</pubDate>
    <dc:creator>sothearith.chanty</dc:creator>
    <dc:date>2005-04-19T01:29:14Z</dc:date>
    <item>
      <title>Cisco PIX 515E Configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353207#M549115</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got one problem with new Cisco PIX515E with 2 Fast Ethernet. Let me explain about my scenario:&lt;/P&gt;&lt;P&gt;LAN-&amp;gt;Switch-&amp;gt;PIX515E-&amp;gt;Internet(DSL)&lt;/P&gt;&lt;P&gt;-LAN: Private IP (192.168.1.0/24)&lt;/P&gt;&lt;P&gt;-Switch: Private IP (192.168.1.253/24)&lt;/P&gt;&lt;P&gt;-PIX515E: (outside)registered ip address: xxx.xxx.xxx.xxx &amp;amp; (inside)private ip address: 192.168.1.254/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With these above scenario, I've 500 users behind my PIX and all those 500 users need to access to internet, mail, and ftp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've already configured with the PDM v3.0 with IOS v.6.3(4) but it is not working.&lt;/P&gt;&lt;P&gt;So anybody can help me by explain me step-by-step about this above issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advanced,&lt;/P&gt;&lt;P&gt;Sothearith Chanty.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353207#M549115</guid>
      <dc:creator>sothearith.chanty</dc:creator>
      <dc:date>2020-02-21T08:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 515E Configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353208#M549116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sothearith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post your current pix config please, make sure to take out any sensitive info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Apr 2005 10:15:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353208#M549116</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2005-04-18T10:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 515E Configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353209#M549117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help, here is my pix config.&lt;/P&gt;&lt;P&gt;===============================================&lt;/P&gt;&lt;P&gt;PIX Version 6.3(4)                  &lt;/P&gt;&lt;P&gt;interface ethernet0 auto shutdown                                 &lt;/P&gt;&lt;P&gt;interface ethernet1 auto shutdown                                 &lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0                                  &lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100                                   &lt;/P&gt;&lt;P&gt;enable password xxxx encrypted                                          &lt;/P&gt;&lt;P&gt;passwd xxxx&lt;/P&gt;&lt;P&gt;encrypted                                 &lt;/P&gt;&lt;P&gt;hostname pixfirewall                    &lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512                                     &lt;/P&gt;&lt;P&gt;fixup protocol ftp 21                     &lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720                             &lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719                                 &lt;/P&gt;&lt;P&gt;fixup protocol http 80                      &lt;/P&gt;&lt;P&gt;fixup protocol rsh 514                      &lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554                       &lt;/P&gt;&lt;P&gt;fixup protocol sip 5060                       &lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060                           &lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000                          &lt;/P&gt;&lt;P&gt;fixup protocol smtp 25                      &lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521                          &lt;/P&gt;&lt;P&gt;fixup protocol tftp 69                      &lt;/P&gt;&lt;P&gt;names     &lt;/P&gt;&lt;P&gt;pager lines 24              &lt;/P&gt;&lt;P&gt;mtu outside 1500                &lt;/P&gt;&lt;P&gt;mtu inside 1500               &lt;/P&gt;&lt;P&gt;ip address outside x.x.x.yyy xxx.xxx.xxx.xxx                                                 &lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.254 255.255.255.0                                             &lt;/P&gt;&lt;P&gt;ip audit info action alarm                          &lt;/P&gt;&lt;P&gt;ip audit attack action alarm                            &lt;/P&gt;&lt;P&gt;no failover           &lt;/P&gt;&lt;P&gt;failover timeout 0:00:00                        &lt;/P&gt;&lt;P&gt;failover poll 15                &lt;/P&gt;&lt;P&gt;no failover ip address outside                              &lt;/P&gt;&lt;P&gt;no failover ip address inside                             &lt;/P&gt;&lt;P&gt;pdm history enable                  &lt;/P&gt;&lt;P&gt;arp timeout 14400                 &lt;/P&gt;&lt;P&gt;timeout xlate           &lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.5 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;===============================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, I got only one registerd ip address and now  already assigned to the outside interface of my pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Sothearith Chanty.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Apr 2005 01:29:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353209#M549117</guid>
      <dc:creator>sothearith.chanty</dc:creator>
      <dc:date>2005-04-19T01:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 515E Configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353210#M549118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;What is missing here is the translation configuration. Use "nat" command to tell the pix what private ip addresses should be translated to access the internet; and the "global" command to specify the public ip address used for translation. In this case the pix outside ip address will be used for translation. Configure:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;# here, any inside ip address (0.0.0.0 0.0.0.0) is translated to the public ip address of the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, you need a default route. Configure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.x&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where x.x.x.x is the ip address of the dsl router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let us know if that helped or if you have questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mustafa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Apr 2005 02:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353210#M549118</guid>
      <dc:creator>mhussein</dc:creator>
      <dc:date>2005-04-19T02:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 515E Configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353211#M549119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sothearith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per Mustafa's post, you need the 'nat' and 'global' statements plus the route outside command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you only have the one public IP address and need to allow SMTP or other service access to the inside interface you can do so as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(in config mode)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; access-list smtp permit tcp any host &lt;YOUR_ONE_PUBLIC_IP&gt; eq smtp&lt;/YOUR_ONE_PUBLIC_IP&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; access-group smtp in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; static (inside,outside) tcp interface smtp &lt;INSIDE_MAIL_SERVER_IP&gt; smtp netmask 255.255.255.255 0 0&lt;/INSIDE_MAIL_SERVER_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Save with : write mem and also issue command: clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: That public ip address for smtp should correspond to your mail MX record ip address!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps and please rate post if it does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Apr 2005 06:35:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353211#M549119</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2005-04-19T06:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 515E Configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353212#M549120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks all of you, but I'm thinking that you are confusing with my explaination, let me explain you again about my scenario:&lt;/P&gt;&lt;P&gt;-I got only one registered ip address which is provided  by my local ISP.&lt;/P&gt;&lt;P&gt;-The connection from my office to my ISP is using ADSL (connected with line phone with ADSL modem, and from that ADSL modem there is one UTP port which I can connect cross-cable to my Fast Ethernet 0 (outside) of my Cisco PIX 515E)&lt;/P&gt;&lt;P&gt;-From the Fast Ethernet 1 (inside) of my Cisco PIX 515E is connected to my LAN's Switch and all my internal users are connected to this switch too.&lt;/P&gt;&lt;P&gt;-I have no routing device&lt;/P&gt;&lt;P&gt;-Here is my registered ip address configuration which have to assign to the outside interface of my current Cisco PIX (Fast Ethernet0):&lt;/P&gt;&lt;P&gt;IP: 203.144.66.144/26&lt;/P&gt;&lt;P&gt;Default Gateway: 203.144.66.129 (server of my ISP)&lt;/P&gt;&lt;P&gt;DNS1: 203.144.65.2&lt;/P&gt;&lt;P&gt;DNS2: 210.80.58.66&lt;/P&gt;&lt;P&gt;-The inside ip's address of Cisco PIX 515E (Fast Ethernet 1) will assign with the private  network address:&lt;/P&gt;&lt;P&gt;IP: 192.168.0.1/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the above configuration I have to allow the internal clients access to internet, mail and ftp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm new to manage this cisco pix, I've read some book only and then I start configure it. I'm very serious with this work, because I must get it done otherwise will be big problem for me.&lt;/P&gt;&lt;P&gt;Please help me if you can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again.&lt;/P&gt;&lt;P&gt;Sothearith Chanty.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Apr 2005 08:13:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353212#M549120</guid>
      <dc:creator>sothearith.chanty</dc:creator>
      <dc:date>2005-04-19T08:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 515E Configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353213#M549121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sothearith,&lt;/P&gt;&lt;P&gt;The configs above should work with your requirements. Have you tried configuring:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;pix(config)#nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;pix(config)#global (outside) 1 interface&lt;/P&gt;&lt;P&gt;pix(config)#route outside 0.0.0.0 0.0.0.0 x.x.66.129  &amp;lt;-- replace this ip with the ISP default gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This config allows internet access for all local hosts on 192.168.0.1/24, using a single public ip address.&lt;/P&gt;&lt;P&gt;Moreover, as per Jay's suggestion above, you can add smtp, web, and http servers all utilizing the same single public ip address.&lt;/P&gt;&lt;P&gt;Does that help at all?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Apr 2005 10:07:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353213#M549121</guid>
      <dc:creator>mhussein</dc:creator>
      <dc:date>2005-04-19T10:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 515E Configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353214#M549127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;start by changing:&lt;/P&gt;&lt;P&gt;interface ethernet0 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet1 auto shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to:&lt;/P&gt;&lt;P&gt;interface ethernet0 auto &lt;/P&gt;&lt;P&gt;interface ethernet1 auto &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default the interfaces are shutdown.&lt;/P&gt;&lt;P&gt;Then do what every one else has been telling you to do namely:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 &lt;INSERT_PUBLIC_IP_ADDRESS&gt; &lt;/INSERT_PUBLIC_IP_ADDRESS&gt;&lt;/P&gt;&lt;P&gt;netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.x &amp;lt;= IP of your dsl device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The global outside can also be implemented like mhussein put it a while back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;pdm is fairly straight forward. To access it from your network, try the following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;pdm location 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then access &lt;A class="jive-link-custom" href="https://192.168.1.254" target="_blank"&gt;https://192.168.1.254&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should work for the PDM. Infact its probably working but you're not using (ssl) https to access it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have fun.&lt;/P&gt;&lt;P&gt;**J.G&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Apr 2005 11:07:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-515e-configuration/m-p/353214#M549127</guid>
      <dc:creator>matjing</dc:creator>
      <dc:date>2005-04-19T11:07:17Z</dc:date>
    </item>
  </channel>
</rss>

