<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 506e in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-506e/m-p/355440#M552001</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes it will allow one side communcation,(connection can only be intiated by inside) for bidirections you need to make another set of rules like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SOURCE&lt;/P&gt;&lt;P&gt;IP &amp;#150;  2.2.2.1/24&lt;/P&gt;&lt;P&gt;Permit&lt;/P&gt;&lt;P&gt;Inside&lt;/P&gt;&lt;P&gt;1.1.1.0/24&lt;/P&gt;&lt;P&gt;Service Group (allow HTTPS)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DESTINATION&lt;/P&gt;&lt;P&gt;IP &amp;#150; 1.1.1.1/24&lt;/P&gt;&lt;P&gt;Permit&lt;/P&gt;&lt;P&gt;Outside&lt;/P&gt;&lt;P&gt;3.3.3.0/25 &amp;#150; The servers of interest reside on this network.&lt;/P&gt;&lt;P&gt;Service Group (allow HTTPS) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;basically swap the source/dst ips, so that outside IPs can also initiate connection to inside ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Feb 2005 23:34:47 GMT</pubDate>
    <dc:creator>nkhawaja</dc:creator>
    <dc:date>2005-02-01T23:34:47Z</dc:date>
    <item>
      <title>PIX 506e</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e/m-p/355439#M552000</link>
      <description>&lt;P&gt;I have two networks that need to communicate using only HTTPS.  In order to configure my PIX 506e firewall, I&amp;#146;ve decided to use PDM v3.0.  The Access Rules configuration is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SOURCE&lt;/P&gt;&lt;P&gt;IP &amp;#150; 1.1.1.1/24&lt;/P&gt;&lt;P&gt;Permit&lt;/P&gt;&lt;P&gt;Inside&lt;/P&gt;&lt;P&gt;1.1.1.0/24&lt;/P&gt;&lt;P&gt;Service Group (allow HTTPS)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DESTINATION&lt;/P&gt;&lt;P&gt;IP &amp;#150; 2.2.2.1/24&lt;/P&gt;&lt;P&gt;Permit&lt;/P&gt;&lt;P&gt;Outside&lt;/P&gt;&lt;P&gt;3.3.3.0/25 &amp;#150; The servers of interest reside on this network.&lt;/P&gt;&lt;P&gt;Service Group (allow HTTPS)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this configuration work to allow HTTPS communications between the networks, at least on one side (going out)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:54:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e/m-p/355439#M552000</guid>
      <dc:creator>saftas.aql</dc:creator>
      <dc:date>2020-02-21T07:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 506e</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e/m-p/355440#M552001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes it will allow one side communcation,(connection can only be intiated by inside) for bidirections you need to make another set of rules like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SOURCE&lt;/P&gt;&lt;P&gt;IP &amp;#150;  2.2.2.1/24&lt;/P&gt;&lt;P&gt;Permit&lt;/P&gt;&lt;P&gt;Inside&lt;/P&gt;&lt;P&gt;1.1.1.0/24&lt;/P&gt;&lt;P&gt;Service Group (allow HTTPS)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DESTINATION&lt;/P&gt;&lt;P&gt;IP &amp;#150; 1.1.1.1/24&lt;/P&gt;&lt;P&gt;Permit&lt;/P&gt;&lt;P&gt;Outside&lt;/P&gt;&lt;P&gt;3.3.3.0/25 &amp;#150; The servers of interest reside on this network.&lt;/P&gt;&lt;P&gt;Service Group (allow HTTPS) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;basically swap the source/dst ips, so that outside IPs can also initiate connection to inside ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Feb 2005 23:34:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e/m-p/355440#M552001</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-02-01T23:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 506e</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e/m-p/355441#M552002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't use the pdm but this looks like you are allowing 'source: 1.1.1.0/24 port 443' and 'dest: 3.3.3.0/25 port 443'.  Keep in mind the source of a HTTPS conversation will be a random high port number.  From the CLI you can be more specific and permit source ports any to dest port 443.  I guess it depends how you defined "allow HTTPS".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2005 20:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e/m-p/355441#M552002</guid>
      <dc:creator>jboyer</dc:creator>
      <dc:date>2005-02-02T20:38:12Z</dc:date>
    </item>
  </channel>
</rss>

