<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 525 static proxied computers cannot go out in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354493#M556426</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey JimWelsh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was talking in reference to any server, not a mail server or a web server particularly.&lt;/P&gt;&lt;P&gt;The actual problem is once the static command is given, the local pc which is mapped cannot reach out to the internet.&lt;/P&gt;&lt;P&gt;This is a strange problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Oct 2004 04:07:17 GMT</pubDate>
    <dc:creator>k.subramaniam</dc:creator>
    <dc:date>2004-10-14T04:07:17Z</dc:date>
    <item>
      <title>Pix 525 static proxied computers cannot go out</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354488#M556421</link>
      <description>&lt;P&gt;Im using the "static (inside,outside).." command to create incomming proxies to webservers and a mailserver.  I can access to the webservers, but the webservers that are proxied to cannot go out to the internet.  Mail doesn't work in either direction.  All other clients can get to all other resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any special acl's or commands that need to be done to allow for the proxied PCs to access the internet?  I thought they would fall under the ACL of any any from that interfaces subnet but its not working.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354488#M556421</guid>
      <dc:creator>edugger</dc:creator>
      <dc:date>2020-02-21T07:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 525 static proxied computers cannot go out</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354489#M556422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I also have faced the same problem some time ago.&lt;/P&gt;&lt;P&gt;I had PIX OS 6.3.3 on PIX 515UR.&lt;/P&gt;&lt;P&gt;I had 2 webservers and 1 mailserver behind it.&lt;/P&gt;&lt;P&gt;The static proxied mail server would not go out to the internet after the static entry, however the web servers coould go out.&lt;/P&gt;&lt;P&gt;I then read somewhere that this might be a IOS bug, so i uploaded 6.3.4.&lt;/P&gt;&lt;P&gt;with this IOS, all servers could not reach out to the internet.&lt;/P&gt;&lt;P&gt;I then uploaded 6.3.3 from the cisco site, not the original one, again all servers not being able to go outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, we give up and the case is under observation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Someone having a clue please help both of us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2004 05:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354489#M556422</guid>
      <dc:creator>k.subramaniam</dc:creator>
      <dc:date>2004-10-13T05:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 525 static proxied computers cannot go out</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354490#M556423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The static(inside,outside) command does two things:  1) it creates a mapping of global IP Address to local IP Address for the inside servers, and 2) it permits traffic to flow from the lower-security to the higher-security interface.  You also need to create an access-list and apply it to the outside interface with the access-group command to permit traffic on specific ports to come into the interface to the inside servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SMTP traffic can be thwarted by the "fixup protocol smtp" command.  Depending on what SMTP servers are in use, I find that I often need to disable this command in order for SMTP traffic to flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as you have an appropriate nat and global command set to allow outbound access, you shoud be OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post your config for examination?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2004 05:15:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354490#M556423</guid>
      <dc:creator>jimwelsh</dc:creator>
      <dc:date>2004-10-13T05:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 525 static proxied computers cannot go out</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354491#M556424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With each static (inside,outside) mapping, you will need an accompanying acl entry, thus:&lt;/P&gt;&lt;P&gt;acces-list ccc permit tcp any host outside_int eq smtp&lt;/P&gt;&lt;P&gt;should do the trick&lt;/P&gt;&lt;P&gt;Fixup allows for only 5 commands, so for testing purposes I suggest you disable it and then, when testing complete, re-activate and test again.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;byron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2004 08:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354491#M556424</guid>
      <dc:creator>bvanniekerk</dc:creator>
      <dc:date>2004-10-13T08:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 525 static proxied computers cannot go out</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354492#M556425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is my config.  Its too big to post so its a txt attachment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2004 13:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354492#M556425</guid>
      <dc:creator>edugger</dc:creator>
      <dc:date>2004-10-13T13:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 525 static proxied computers cannot go out</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354493#M556426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey JimWelsh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was talking in reference to any server, not a mail server or a web server particularly.&lt;/P&gt;&lt;P&gt;The actual problem is once the static command is given, the local pc which is mapped cannot reach out to the internet.&lt;/P&gt;&lt;P&gt;This is a strange problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Oct 2004 04:07:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-static-proxied-computers-cannot-go-out/m-p/354493#M556426</guid>
      <dc:creator>k.subramaniam</dc:creator>
      <dc:date>2004-10-14T04:07:17Z</dc:date>
    </item>
  </channel>
</rss>

