<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Validate PIX 515e Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/validate-pix-515e-configuration/m-p/317047#M556789</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Patrick - Thanks for the reply. I've changed the VPN Pool which should also help with security if I choose to place more restrictive rights on it in the future. Thanks for the tip. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Oct 2004 18:49:09 GMT</pubDate>
    <dc:creator>ryanwilhelm</dc:creator>
    <dc:date>2004-10-04T18:49:09Z</dc:date>
    <item>
      <title>Validate PIX 515e Configuration</title>
      <link>https://community.cisco.com/t5/network-security/validate-pix-515e-configuration/m-p/317045#M556782</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I'm trying to validate my configuration before going live and would appreciate if anyone could take a look and make recommendations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to accomplish the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Any External user connects to DMZ web server on port 80 (though ultimately 443 will be used), the dmz web server makes a connection to oracle (sqlnet) which sends packets and should be able to receive the replies back&lt;/P&gt;&lt;P&gt;2. smtp connections come in through a public address to a dmz box which in turn sends the message to an internal (inside interface) smtp box for delivery&lt;/P&gt;&lt;P&gt;3. Remote workers may connect to a public ip (204.50.125.138 in the example) on port 443 which will then allow a connection into the inside interface to connect to an internal web server (not a good idea, but i'm working with what i have).&lt;/P&gt;&lt;P&gt;4. I would like to pretty much allow all packets routed from a higher security level (100) to route out the outside interface without being blocked and receive replies back. Do I have it set up correctly?&lt;/P&gt;&lt;P&gt;5. Support VPN users connecting to the Inside nework via the Cisco Secure VPN client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've attached my config (with entries changed to protect the innocent). Any feedback would be appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:39:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/validate-pix-515e-configuration/m-p/317045#M556782</guid>
      <dc:creator>ryanwilhelm</dc:creator>
      <dc:date>2020-02-21T07:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: Validate PIX 515e Configuration</title>
      <link>https://community.cisco.com/t5/network-security/validate-pix-515e-configuration/m-p/317046#M556786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Feedback config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) Never publish public IPs in your config examples.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) You used a VPN IP pool that has the same range as the internal interface. This works but might give problems in routing. I usually uses another IP Range for that. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.) Everything else look good, You could use instead of this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) tcp 10.20.x.y smtp 192.168.0.z smtp netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a NAT0 or static for the whole network so that no translation occours for all inside to dmz or web interface traffic. But this should work like that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sincerely&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Oct 2004 16:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/validate-pix-515e-configuration/m-p/317046#M556786</guid>
      <dc:creator>Patrick Iseli</dc:creator>
      <dc:date>2004-10-04T16:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Validate PIX 515e Configuration</title>
      <link>https://community.cisco.com/t5/network-security/validate-pix-515e-configuration/m-p/317047#M556789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Patrick - Thanks for the reply. I've changed the VPN Pool which should also help with security if I choose to place more restrictive rights on it in the future. Thanks for the tip. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Oct 2004 18:49:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/validate-pix-515e-configuration/m-p/317047#M556789</guid>
      <dc:creator>ryanwilhelm</dc:creator>
      <dc:date>2004-10-04T18:49:09Z</dc:date>
    </item>
  </channel>
</rss>

