<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Please help me with PIX 501 basic configuration... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/please-help-me-with-pix-501-basic-configuration/m-p/355928#M556370</link>
    <description>&lt;P&gt;Please, could you help me with basic config with access from inside network 192.168.1.0/24 to outside network 192.168.7.0/24. I have problem with icmp(ping) from inside to outside and other serveces as ftp and http on outside host 192.168.7.1. This is my config...(I'm beginer) &lt;span class="lia-unicode-emoji" title=":monkey_face:"&gt;🐵&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(192.168.1.2 is my comp) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of firewall command: "sh runn" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved &lt;/P&gt;&lt;P&gt;: &lt;/P&gt;&lt;P&gt;PIX Version 6.2(2) &lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0 &lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100 &lt;/P&gt;&lt;P&gt;enable password xxxx&lt;/P&gt;&lt;P&gt;passwd xxxx &lt;/P&gt;&lt;P&gt;hostname firewall &lt;/P&gt;&lt;P&gt;domain-name firewall.cz &lt;/P&gt;&lt;P&gt;fixup protocol ftp 21 &lt;/P&gt;&lt;P&gt;fixup protocol http 80 &lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720 &lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719 &lt;/P&gt;&lt;P&gt;fixup protocol ils 389 &lt;/P&gt;&lt;P&gt;fixup protocol rsh 514 &lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554 &lt;/P&gt;&lt;P&gt;fixup protocol smtp 25 &lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521 &lt;/P&gt;&lt;P&gt;fixup protocol sip 5060 &lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000 &lt;/P&gt;&lt;P&gt;names &lt;/P&gt;&lt;P&gt;access-list inside_access_in permit icmp any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any &lt;/P&gt;&lt;P&gt;pager lines 24 &lt;/P&gt;&lt;P&gt;interface ethernet0 10baset &lt;/P&gt;&lt;P&gt;interface ethernet1 10full &lt;/P&gt;&lt;P&gt;icmp permit any outside &lt;/P&gt;&lt;P&gt;icmp permit any inside &lt;/P&gt;&lt;P&gt;mtu outside 1500 &lt;/P&gt;&lt;P&gt;mtu inside 1500 &lt;/P&gt;&lt;P&gt;ip address outside 192.168.7.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip audit info action alarm &lt;/P&gt;&lt;P&gt;ip audit attack action alarm &lt;/P&gt;&lt;P&gt;pdm location 192.168.1.2 255.255.255.255 inside &lt;/P&gt;&lt;P&gt;pdm history enable &lt;/P&gt;&lt;P&gt;arp timeout 14400 &lt;/P&gt;&lt;P&gt;nat (inside) 0 192.168.1.0 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside &lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside &lt;/P&gt;&lt;P&gt;rip outside default version 1 &lt;/P&gt;&lt;P&gt;rip inside default version 1 &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.7.1 1 &lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00 &lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00 &lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;http server enable &lt;/P&gt;&lt;P&gt;http 192.168.1.2 255.255.255.255 inside &lt;/P&gt;&lt;P&gt;no snmp-server location &lt;/P&gt;&lt;P&gt;no snmp-server contact &lt;/P&gt;&lt;P&gt;snmp-server community public &lt;/P&gt;&lt;P&gt;no snmp-server enable traps &lt;/P&gt;&lt;P&gt;floodguard enable &lt;/P&gt;&lt;P&gt;no sysopt route dnat &lt;/P&gt;&lt;P&gt;telnet 192.168.1.2 255.255.255.255 inside &lt;/P&gt;&lt;P&gt;telnet timeout 5 &lt;/P&gt;&lt;P&gt;ssh timeout 5 &lt;/P&gt;&lt;P&gt;terminal width 80 &lt;/P&gt;&lt;P&gt;Cryptochecksum:xxxxx &lt;/P&gt;&lt;P&gt;: end &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:40:48 GMT</pubDate>
    <dc:creator>j.rock</dc:creator>
    <dc:date>2020-02-21T07:40:48Z</dc:date>
    <item>
      <title>Please help me with PIX 501 basic configuration...</title>
      <link>https://community.cisco.com/t5/network-security/please-help-me-with-pix-501-basic-configuration/m-p/355928#M556370</link>
      <description>&lt;P&gt;Please, could you help me with basic config with access from inside network 192.168.1.0/24 to outside network 192.168.7.0/24. I have problem with icmp(ping) from inside to outside and other serveces as ftp and http on outside host 192.168.7.1. This is my config...(I'm beginer) &lt;span class="lia-unicode-emoji" title=":monkey_face:"&gt;🐵&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(192.168.1.2 is my comp) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of firewall command: "sh runn" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved &lt;/P&gt;&lt;P&gt;: &lt;/P&gt;&lt;P&gt;PIX Version 6.2(2) &lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0 &lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100 &lt;/P&gt;&lt;P&gt;enable password xxxx&lt;/P&gt;&lt;P&gt;passwd xxxx &lt;/P&gt;&lt;P&gt;hostname firewall &lt;/P&gt;&lt;P&gt;domain-name firewall.cz &lt;/P&gt;&lt;P&gt;fixup protocol ftp 21 &lt;/P&gt;&lt;P&gt;fixup protocol http 80 &lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720 &lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719 &lt;/P&gt;&lt;P&gt;fixup protocol ils 389 &lt;/P&gt;&lt;P&gt;fixup protocol rsh 514 &lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554 &lt;/P&gt;&lt;P&gt;fixup protocol smtp 25 &lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521 &lt;/P&gt;&lt;P&gt;fixup protocol sip 5060 &lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000 &lt;/P&gt;&lt;P&gt;names &lt;/P&gt;&lt;P&gt;access-list inside_access_in permit icmp any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any &lt;/P&gt;&lt;P&gt;pager lines 24 &lt;/P&gt;&lt;P&gt;interface ethernet0 10baset &lt;/P&gt;&lt;P&gt;interface ethernet1 10full &lt;/P&gt;&lt;P&gt;icmp permit any outside &lt;/P&gt;&lt;P&gt;icmp permit any inside &lt;/P&gt;&lt;P&gt;mtu outside 1500 &lt;/P&gt;&lt;P&gt;mtu inside 1500 &lt;/P&gt;&lt;P&gt;ip address outside 192.168.7.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip audit info action alarm &lt;/P&gt;&lt;P&gt;ip audit attack action alarm &lt;/P&gt;&lt;P&gt;pdm location 192.168.1.2 255.255.255.255 inside &lt;/P&gt;&lt;P&gt;pdm history enable &lt;/P&gt;&lt;P&gt;arp timeout 14400 &lt;/P&gt;&lt;P&gt;nat (inside) 0 192.168.1.0 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside &lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside &lt;/P&gt;&lt;P&gt;rip outside default version 1 &lt;/P&gt;&lt;P&gt;rip inside default version 1 &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.7.1 1 &lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00 &lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00 &lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;http server enable &lt;/P&gt;&lt;P&gt;http 192.168.1.2 255.255.255.255 inside &lt;/P&gt;&lt;P&gt;no snmp-server location &lt;/P&gt;&lt;P&gt;no snmp-server contact &lt;/P&gt;&lt;P&gt;snmp-server community public &lt;/P&gt;&lt;P&gt;no snmp-server enable traps &lt;/P&gt;&lt;P&gt;floodguard enable &lt;/P&gt;&lt;P&gt;no sysopt route dnat &lt;/P&gt;&lt;P&gt;telnet 192.168.1.2 255.255.255.255 inside &lt;/P&gt;&lt;P&gt;telnet timeout 5 &lt;/P&gt;&lt;P&gt;ssh timeout 5 &lt;/P&gt;&lt;P&gt;terminal width 80 &lt;/P&gt;&lt;P&gt;Cryptochecksum:xxxxx &lt;/P&gt;&lt;P&gt;: end &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:40:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help-me-with-pix-501-basic-configuration/m-p/355928#M556370</guid>
      <dc:creator>j.rock</dc:creator>
      <dc:date>2020-02-21T07:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Please help me with PIX 501 basic configuration...</title>
      <link>https://community.cisco.com/t5/network-security/please-help-me-with-pix-501-basic-configuration/m-p/355929#M556371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your current configuration should allow ping to be successful. Have you made sure that 192.168.7.1 has a route back to 192.168.1.0/24 via 192.168.7.2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access-list you are binding to the inside interface will only allow icmp to be permitted outwards from hosts residing on the inside. If you want these hosts to be able to telnet, ftp, ssh, etc. outwards then you need to modify the access-list accordingly. Again make sure that the device you are connecting to knows how to get back to the subnet you are connecting from.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2004 11:11:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help-me-with-pix-501-basic-configuration/m-p/355929#M556371</guid>
      <dc:creator>a.awan</dc:creator>
      <dc:date>2004-10-13T11:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: Please help me with PIX 501 basic configuration...</title>
      <link>https://community.cisco.com/t5/network-security/please-help-me-with-pix-501-basic-configuration/m-p/355930#M556372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The host 192.168.7.1 is my test server(with ftp, http, tftp server).(I set only IP address a mask without gateway and dns settings) It's very simple config. (my pc &amp;gt; fw &amp;gt; server)&lt;/P&gt;&lt;P&gt;I don't ping also to outside fw interface from my pc....why? Thanks. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2004 11:43:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help-me-with-pix-501-basic-configuration/m-p/355930#M556372</guid>
      <dc:creator>j.rock</dc:creator>
      <dc:date>2004-10-13T11:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Please help me with PIX 501 basic configuration...</title>
      <link>https://community.cisco.com/t5/network-security/please-help-me-with-pix-501-basic-configuration/m-p/355931#M556373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The host 192.168.7.1 needs to know how to get back to the 192.68.1.0/24 subnet. You can either add a static route on this host or you can configure this host with a default gateway which will be the outside interface of the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot ping from a host on one interface of the PIX to the IP of another PIX interface. That is why you are unable to ping the outside interface of the PIX from your PC on the inside interface. I am sure you can ping from your PC to the PIX inside interface and from the server to the PIX outside interface. This is normal so do not be concerned about it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After adding the default gateway on both the server and your internal PC you should be able to ping between them. Your internal PC should have the PIX inside interface as the default gateway while your outside server should have the PIX outside interface as the default gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2004 13:20:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help-me-with-pix-501-basic-configuration/m-p/355931#M556373</guid>
      <dc:creator>a.awan</dc:creator>
      <dc:date>2004-10-13T13:20:35Z</dc:date>
    </item>
  </channel>
</rss>

