<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 506 x Siebel Application in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-506-x-siebel-application/m-p/378691#M549902</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you think about using the 'established' command? It permits "return connections on ports other than those used for the originating connection based on an established connection" (from the Command Reference).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- PIX Command Reference, version 6.3:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/df.htm#wp1028903" target="_blank"&gt;http://cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/df.htm#wp1028903&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be aware of the security risks this implies...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example (assuming initial connection behind PIX, to Siebel server behind concentrator):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;established tcp 0 siebel-port permitfrom tcp siebel-second-channel-src-port permitto tcp siebel-second-channel-dst-port&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico Rodriguez&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Apr 2005 01:06:33 GMT</pubDate>
    <dc:creator>fedrodri</dc:creator>
    <dc:date>2005-04-06T01:06:33Z</dc:date>
    <item>
      <title>PIX 506 x Siebel Application</title>
      <link>https://community.cisco.com/t5/network-security/pix-506-x-siebel-application/m-p/378689#M549893</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a IPsec tunel from a remote site (PIX 506) to a 3020 Concentrator. Users use all applications without problem except Siebel (client server application with database access). It seems that Siebel creates secondaries dynamic TCP connections and PIX is droping these packets. As these connections are not stablished before, PIX is dropping these packets. I have the message 106015 in the log file. According PIX documentation ´If the SYN flag is not set, and there is not an existing connection, the firewall discards the packet´.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does someone have a tip to overcome this situation ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;  &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:02:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506-x-siebel-application/m-p/378689#M549893</guid>
      <dc:creator>jrmendes</dc:creator>
      <dc:date>2020-02-21T08:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 506 x Siebel Application</title>
      <link>https://community.cisco.com/t5/network-security/pix-506-x-siebel-application/m-p/378690#M549897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The document IP Security Troubleshooting - Understanding and Using debug Commands has more information on troubleshooting IPSec.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/customer/707/ipsec_debug.html" target="_blank"&gt;http://www.cisco.com/warp/customer/707/ipsec_debug.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Apr 2005 17:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506-x-siebel-application/m-p/378690#M549897</guid>
      <dc:creator>owillins</dc:creator>
      <dc:date>2005-04-05T17:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 506 x Siebel Application</title>
      <link>https://community.cisco.com/t5/network-security/pix-506-x-siebel-application/m-p/378691#M549902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you think about using the 'established' command? It permits "return connections on ports other than those used for the originating connection based on an established connection" (from the Command Reference).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- PIX Command Reference, version 6.3:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/df.htm#wp1028903" target="_blank"&gt;http://cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/df.htm#wp1028903&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be aware of the security risks this implies...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example (assuming initial connection behind PIX, to Siebel server behind concentrator):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;established tcp 0 siebel-port permitfrom tcp siebel-second-channel-src-port permitto tcp siebel-second-channel-dst-port&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico Rodriguez&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2005 01:06:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506-x-siebel-application/m-p/378691#M549902</guid>
      <dc:creator>fedrodri</dc:creator>
      <dc:date>2005-04-06T01:06:33Z</dc:date>
    </item>
  </channel>
</rss>

