<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515E configuration help require in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-help-require/m-p/366825#M556210</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi dear sachin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for ur reply I have removed my NAT from router and set PAT on PIX but still I am facing some problem :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually I have set "access-list permit icmp any any echo-reply" time-exceeded &amp;amp; unreachable.......so now I am able to ping from my PIX console to my ISP GW ip...but still I am not able to access internet or ping from my inside n/w PCs to internet GW. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. find the below details of my n/w and config.and suggest where am I missing? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need ur help badly, now it's a question of my output....please help me ASAP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't remove my border router because it has been sold to my customers earlier for my SUN servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. note my yahoo messenger ID is &lt;A href="mailto:barodians_us@yahoo.com"&gt;barodians_us@yahoo.com&lt;/A&gt; If u are not disturb u can come on yahoo for chatting to suggest me online. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;N/W setup: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#My router inside ip (172.16.29.1/24)--Router outside (10.1.1.1/24)--PIX inside (10.1.1.2/24)--PIX outside (208.144.230.197 255.255.255.224-ISP supplied) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#My ISP Gateway address is 208.144.230.200 &lt;/P&gt;&lt;P&gt;#My DNS servers are 208.144.230.1 and 208.144.230.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#VLAN Config: &lt;/P&gt;&lt;P&gt;boot-start-marker &lt;/P&gt;&lt;P&gt;boot-end-marker &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no aaa new-model &lt;/P&gt;&lt;P&gt;ip subnet-zero &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;no ip dhcp conflict logging &lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.29.1 172.16.29.240 &lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.29.250 172.16.29.254 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface FastEthernet0/0 &lt;/P&gt;&lt;P&gt;ip address 208.144.230.197 255.255.255.224 &lt;/P&gt;&lt;P&gt;duplex auto &lt;/P&gt;&lt;P&gt;speed auto &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface FastEthernet0/1 &lt;/P&gt;&lt;P&gt;ip address 10.1.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;duplex auto &lt;/P&gt;&lt;P&gt;speed auto &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;ip http server &lt;/P&gt;&lt;P&gt;ip classless &lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.1.1.2 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;access-list 7 permit 172.16.29.0 0.0.0.255 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#PIX 515E config: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(3) &lt;/P&gt;&lt;P&gt;interface ethernet0 auto &lt;/P&gt;&lt;P&gt;interface ethernet1 auto &lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0 &lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname VLANPIX &lt;/P&gt;&lt;P&gt;domain-name VLAN &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21 &lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720 &lt;/P&gt;&lt;P&gt;fixup protocol http 80 &lt;/P&gt;&lt;P&gt;fixup protocol rsh 514 &lt;/P&gt;&lt;P&gt;fixup protocol smtp 25 &lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521 &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit icmp any any &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq pop3 &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq domain &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit udp any any eq domain &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq telnet &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq h323 &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq https &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq 1863 &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq ftp-data &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq ftp &lt;/P&gt;&lt;P&gt;access-list acl_outbound deny ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit icmp any any &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq 1863 &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq ftp &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq ftp-data &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq h323 &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq pop3 &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq domain &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit udp any any eq domain &lt;/P&gt;&lt;P&gt;access-list acl_inbound deny ip any any &lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 208.144.230.197 255.255.255.224 &lt;/P&gt;&lt;P&gt;ip address inside 10.1.1.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl_inbound in interface outside &lt;/P&gt;&lt;P&gt;access-group acl_outbound in interface inside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 208.144.230.200 1 &lt;/P&gt;&lt;P&gt;floodguard enable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 10.1.1.0 255.255.255.0 inside &lt;/P&gt;&lt;P&gt;telnet timeout 5 &lt;/P&gt;&lt;P&gt;ssh timeout 5 &lt;/P&gt;&lt;P&gt;console timeout 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks. &lt;/P&gt;&lt;P&gt;Regards, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hiren Mehta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Oct 2004 14:19:24 GMT</pubDate>
    <dc:creator>hiruannaofit</dc:creator>
    <dc:date>2004-10-22T14:19:24Z</dc:date>
    <item>
      <title>PIX 515E configuration help require</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-help-require/m-p/366822#M556203</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi.Actually I need some help for PIX 515E.Pls. refer the scenario,design &amp;amp; suggest?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. find the following details and attached VLAN Router configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# I want to set like &lt;/P&gt;&lt;P&gt;"My LAN on CISCO 2900 switch (IP range 172.16.29.X... 25 PCs) -- VLAN Router - CISCO PIX ----ISP Public IP"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# Right now it's &lt;/P&gt;&lt;P&gt;"My LAN on CISCO 2900 - VLAN Router (Outside) - ISP"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router &amp;amp; PIX details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Router inside ip - 172.16.29.1 (Inside IP as it is very critical which can't be changed)&lt;/P&gt;&lt;P&gt;#Router outside ip - Which ip should I use? (I tried with 1.1.1.1 255.255.255.0)&lt;/P&gt;&lt;P&gt;#PIX outside ip - Which ip should I use? (My ISP IP? - I tried with 208.144.230.197 which is right now my router's outside)&lt;/P&gt;&lt;P&gt;#PIX inside ip - Which ip should I use? (I tried with 1.1.1.2 255.255.255.0)&lt;/P&gt;&lt;P&gt;#My ISP connection is direct from ISP GW to one ethernet cat 5 on my VLAN router&lt;/P&gt;&lt;P&gt;#I would like to permit www,FTP,web based mail like Yahoomail..etc.. &amp;amp; messenger services&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLAN Router Config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 1028 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.3&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;no service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname VLANRouter&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;enable password gcsroot&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no aaa new-model&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip dhcp conflict logging&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.29.1 172.16.29.240&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.29.250 172.16.29.254&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool dhcppool&lt;/P&gt;&lt;P&gt;   network 172.16.29.0 255.255.255.0&lt;/P&gt;&lt;P&gt;   dns-server 208.144.230.1 208.144.230.2 &lt;/P&gt;&lt;P&gt;   default-router 172.16.29.1 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;controller E1 0/0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;controller E1 0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 208.144.230.197 255.255.255.224&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; ip address 172.16.29.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip nat inside source list 7 interface FastEthernet0/0 overload&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 208.144.230.200&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 7 permit 172.16.29.0 0.0.0.255&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hiren Mehta.&lt;/P&gt;&lt;P&gt;ORG Informatics Ltd.&lt;/P&gt;&lt;P&gt;Bamako, MALI&lt;/P&gt;&lt;P&gt;AFRICA&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:41:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-configuration-help-require/m-p/366822#M556203</guid>
      <dc:creator>hiruannaofit</dc:creator>
      <dc:date>2020-02-21T07:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E configuration help require</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-help-require/m-p/366823#M556204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi hiren,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the answers below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Router inside ip - 172.16.29.1 (Inside IP as it is very critical which can't be changed) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you put the PIX inbetween the router and your switch, you have to put the PIX inside IP as 172.16.29.1 and change the router's inside subnet to someother pool. Do the PAT on the PIX, instead of the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Router outside ip - Which ip should I use? (I tried with 1.1.1.1 255.255.255.0) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router outside IP will be the one given by the ISP.. The ISP would have given a public IP for the WAN link. This cannot be changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#PIX outside ip - Which ip should I use? (My ISP IP? - I tried with 208.144.230.197 which is right now my router's outside) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX outside IP should be a global one. ISP would have given you a LAN subnet. Use that. In this case, the router's inside interface will have an IP from this same subnet..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#PIX inside ip - Which ip should I use? (I tried with 1.1.1.2 255.255.255.0) &lt;/P&gt;&lt;P&gt;PIX inside should be 172.16.29.1 , which will be the default gateway for all PCs. If you change this subnet, then all the PCs should have an IP address on the same subnet as decided.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#My ISP connection is direct from ISP GW to one ethernet cat 5 on my VLAN router &lt;/P&gt;&lt;P&gt;did not get this.. is it on the internet router or on the switch ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#I would like to permit www,FTP,web based mail like Yahoomail..etc.. &amp;amp; messenger services &lt;/P&gt;&lt;P&gt;If all these have to be permitted from inside to outside, you need not open anything.. by default all traffic from inside to outside is permitted (unless u put an access-list and deny )...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Oct 2004 06:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-configuration-help-require/m-p/366823#M556204</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2004-10-16T06:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E configuration help require</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-help-require/m-p/366824#M556207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Sachin Raja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for ur prompt and appropriate reply.Actually u have cleared my confusion exactly I needed but still I have decided my PIX config. with respect to customer requirement. I will test it tonight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See u.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Oct 2004 10:27:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-configuration-help-require/m-p/366824#M556207</guid>
      <dc:creator>hiruannaofit</dc:creator>
      <dc:date>2004-10-16T10:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E configuration help require</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-help-require/m-p/366825#M556210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi dear sachin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for ur reply I have removed my NAT from router and set PAT on PIX but still I am facing some problem :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually I have set "access-list permit icmp any any echo-reply" time-exceeded &amp;amp; unreachable.......so now I am able to ping from my PIX console to my ISP GW ip...but still I am not able to access internet or ping from my inside n/w PCs to internet GW. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. find the below details of my n/w and config.and suggest where am I missing? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need ur help badly, now it's a question of my output....please help me ASAP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't remove my border router because it has been sold to my customers earlier for my SUN servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. note my yahoo messenger ID is &lt;A href="mailto:barodians_us@yahoo.com"&gt;barodians_us@yahoo.com&lt;/A&gt; If u are not disturb u can come on yahoo for chatting to suggest me online. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;N/W setup: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#My router inside ip (172.16.29.1/24)--Router outside (10.1.1.1/24)--PIX inside (10.1.1.2/24)--PIX outside (208.144.230.197 255.255.255.224-ISP supplied) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#My ISP Gateway address is 208.144.230.200 &lt;/P&gt;&lt;P&gt;#My DNS servers are 208.144.230.1 and 208.144.230.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#VLAN Config: &lt;/P&gt;&lt;P&gt;boot-start-marker &lt;/P&gt;&lt;P&gt;boot-end-marker &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no aaa new-model &lt;/P&gt;&lt;P&gt;ip subnet-zero &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;no ip dhcp conflict logging &lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.29.1 172.16.29.240 &lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.29.250 172.16.29.254 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface FastEthernet0/0 &lt;/P&gt;&lt;P&gt;ip address 208.144.230.197 255.255.255.224 &lt;/P&gt;&lt;P&gt;duplex auto &lt;/P&gt;&lt;P&gt;speed auto &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface FastEthernet0/1 &lt;/P&gt;&lt;P&gt;ip address 10.1.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;duplex auto &lt;/P&gt;&lt;P&gt;speed auto &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;ip http server &lt;/P&gt;&lt;P&gt;ip classless &lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.1.1.2 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;access-list 7 permit 172.16.29.0 0.0.0.255 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#PIX 515E config: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(3) &lt;/P&gt;&lt;P&gt;interface ethernet0 auto &lt;/P&gt;&lt;P&gt;interface ethernet1 auto &lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0 &lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname VLANPIX &lt;/P&gt;&lt;P&gt;domain-name VLAN &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21 &lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720 &lt;/P&gt;&lt;P&gt;fixup protocol http 80 &lt;/P&gt;&lt;P&gt;fixup protocol rsh 514 &lt;/P&gt;&lt;P&gt;fixup protocol smtp 25 &lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521 &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit icmp any any &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq pop3 &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq domain &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit udp any any eq domain &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq telnet &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq h323 &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq https &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq 1863 &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq ftp-data &lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq ftp &lt;/P&gt;&lt;P&gt;access-list acl_outbound deny ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit icmp any any &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq 1863 &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq ftp &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq ftp-data &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq h323 &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq pop3 &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq domain &lt;/P&gt;&lt;P&gt;access-list acl_inbound permit udp any any eq domain &lt;/P&gt;&lt;P&gt;access-list acl_inbound deny ip any any &lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 208.144.230.197 255.255.255.224 &lt;/P&gt;&lt;P&gt;ip address inside 10.1.1.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl_inbound in interface outside &lt;/P&gt;&lt;P&gt;access-group acl_outbound in interface inside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 208.144.230.200 1 &lt;/P&gt;&lt;P&gt;floodguard enable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 10.1.1.0 255.255.255.0 inside &lt;/P&gt;&lt;P&gt;telnet timeout 5 &lt;/P&gt;&lt;P&gt;ssh timeout 5 &lt;/P&gt;&lt;P&gt;console timeout 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks. &lt;/P&gt;&lt;P&gt;Regards, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hiren Mehta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2004 14:19:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-configuration-help-require/m-p/366825#M556210</guid>
      <dc:creator>hiruannaofit</dc:creator>
      <dc:date>2004-10-22T14:19:24Z</dc:date>
    </item>
  </channel>
</rss>

