<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Outlook web access over pix firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505221#M557697</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;use HTTPS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://2xx.1xx.xxx.xx6/exchange" target="_blank"&gt;https://2xx.1xx.xxx.xx6/exchange&lt;/A&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 May 2005 06:41:36 GMT</pubDate>
    <dc:creator>a.alekseev</dc:creator>
    <dc:date>2005-05-30T06:41:36Z</dc:date>
    <item>
      <title>Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505212#M557687</link>
      <description>&lt;P&gt;Hi Firewall Guru,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody here can help me to set-up my cisco firewall to work for external outlook web access.I have changed some parameters and make it run internally.. however I can not access it externally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means, when I open outlook web access on our lan it works, but when I try to open it via internet ISP I can't open it.. "page can not be found"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls advice how did you resolved it thru pix firewall configuration if any of you encountered the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jeric&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505212#M557687</guid>
      <dc:creator>jeric_saldua</dc:creator>
      <dc:date>2020-02-21T08:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505213#M557688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;post your config&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 May 2005 00:16:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505213#M557688</guid>
      <dc:creator>froggy3132000</dc:creator>
      <dc:date>2005-05-29T00:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505214#M557690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls find attached files.. hope you can help me on this.. right now.. i dont have problem on my internet, everything is ok.. mail server is ok.. when I access outlook web access internally no problem as well, my only problem is I can not open it outside our network.. but i can ping it from the outside.. which means the public ip address for my mail server is reachable from the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope you can help me on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;jeric&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 May 2005 02:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505214#M557690</guid>
      <dc:creator>jeric_saldua</dc:creator>
      <dc:date>2005-05-29T02:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505215#M557691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;pls add the following &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ACL_OUT permit tcp any host 2xx.1xx.xxx.xx6 eq 443 &lt;/P&gt;&lt;P&gt;ip address outside 2xx.1xx.xxx.xx6 255.255.255.252&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 443 192.168.1.4 443 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;access-group ACL_OUT in interface outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 May 2005 03:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505215#M557691</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-05-29T03:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505216#M557692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks so much for your prompt response..I follow your suggested changes and tested it.. however it still not working..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls check the config below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 192.168.1.4 inside_mail_server&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 192.168.1.80 255.255.255.240 any&lt;/P&gt;&lt;P&gt;access-list 101 permit ip any 192.168.1.80 255.255.255.240&lt;/P&gt;&lt;P&gt;access-list ACL_OUT permit tcp any host 2xx.1xx.1xx.2xx eq smtp&lt;/P&gt;&lt;P&gt;access-list ACL_OUT permit tcp any host 2xx.1xx.1xx.2xx eq pop3&lt;/P&gt;&lt;P&gt;access-list ACL_OUT permit tcp any host 2xx.1xx.1xx.2xx eq https&lt;/P&gt;&lt;P&gt;access-list ACL_OUT permit tcp any host 2xx.1xx.1xx.2xx eq www&lt;/P&gt;&lt;P&gt;access-list ACL_OUT permit tcp any host 2xx.1xx.1xx.2xx eq 135&lt;/P&gt;&lt;P&gt;access-list ACL_OUT deny udp any any eq 1214&lt;/P&gt;&lt;P&gt;access-list ACL_OUT deny tcp any any eq 5000&lt;/P&gt;&lt;P&gt;access-list ACL_OUT deny tcp any any eq 11999&lt;/P&gt;&lt;P&gt;access-list ACL_OUT deny udp any any eq 5010&lt;/P&gt;&lt;P&gt;access-list ACL_OUT deny tcp any any eq 1214&lt;/P&gt;&lt;P&gt;access-list ACL_OUT deny tcp any any eq 1863&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_30 permit ip any 192.168.1.80 255.255.255.240&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 2xx.1xx.1xx.2xx 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface inside&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;ip local pool VPN_POOL 192.168.1.81-192.168.1.94&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 101&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface smtp inside_mail_server smtp netmask 255.2&lt;/P&gt;&lt;P&gt;55.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface pop3 inside_mail_server pop3 netmask 255.2&lt;/P&gt;&lt;P&gt;55.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface https inside_mail_server https netmask 255&lt;/P&gt;&lt;P&gt;.255.255.255 0 0&lt;/P&gt;&lt;P&gt;access-group ACL_OUT in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you could guide on how to resolve it.. additional information. I use 1 ip address only for outside xlation at the same time am using it for static mapping for my mail server inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will look forward for your kind response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeric&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 02:35:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505216#M557692</guid>
      <dc:creator>jeric_saldua</dc:creator>
      <dc:date>2005-05-30T02:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505217#M557693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you try "clear xlate" after making some changes?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 03:48:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505217#M557693</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-05-30T03:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505218#M557694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did. but still page can not be displayed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;jeric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 04:12:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505218#M557694</guid>
      <dc:creator>jeric_saldua</dc:creator>
      <dc:date>2005-05-30T04:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505219#M557695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How did you check it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 04:29:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505219#M557695</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-05-30T04:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505220#M557696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My collegue is working at home and he is the one who is testing it. he test it by doing this &amp;gt;  open internet explorer and on the address bar he type &lt;A class="jive-link-custom" href="http:2xx.1xx.xxx.xx6/exchange" target="_blank"&gt;http:2xx.1xx.xxx.xx6/exchange&lt;/A&gt; (ip address for outlook web access). "page can not be displayed" . But he can ping the ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your kind assistance, I really appreciate your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jeric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 05:17:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505220#M557696</guid>
      <dc:creator>jeric_saldua</dc:creator>
      <dc:date>2005-05-30T05:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505221#M557697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;use HTTPS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://2xx.1xx.xxx.xx6/exchange" target="_blank"&gt;https://2xx.1xx.xxx.xx6/exchange&lt;/A&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 06:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505221#M557697</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-05-30T06:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505222#M557698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again for your prompt response.. I just try it but to no avail. same error...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;jeric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 07:18:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505222#M557698</guid>
      <dc:creator>jeric_saldua</dc:creator>
      <dc:date>2005-05-30T07:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505223#M557699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;could you show&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"sh access-list ACL_OUT"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you see any macthes for "access-list ACL_OUT permit tcp any host 2xx.1xx.xxx.xx6 eq https"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 07:39:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505223#M557699</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-05-30T07:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505224#M557700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's matches, but I think the matches came from internal users who access it on our LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls check below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall# sh access-list ACL_OUT&lt;/P&gt;&lt;P&gt;access-list ACL_OUT; 11 elements&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 1 permit tcp any host 2xx.1xx.xxx.xx6 eq smtp (hitcnt=4&lt;/P&gt;&lt;P&gt;71)&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 2 permit tcp any host 2xx.1xx.xxx.xx6 eq pop3 (hitcnt=0&lt;/P&gt;&lt;P&gt;)&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 3 permit tcp any host 2xx.1xx.xxx.xx6 eq https (hitcnt=&lt;/P&gt;&lt;P&gt;19)&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 4 permit tcp any host 2xx.1xx.xxx.xx6 eq www (hitcnt=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 5 permit tcp any host 2xx.1xx.xxx.xx6 eq 135 (hitcnt=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 6 deny udp any any eq 1214 (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 7 deny tcp any any eq 5000 (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 8 deny tcp any any eq 11999 (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 9 deny udp any any eq 5010 (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 10 deny tcp any any eq 1214 (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 11 deny tcp any any eq 1863 (hitcnt=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 08:30:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505224#M557700</guid>
      <dc:creator>jeric_saldua</dc:creator>
      <dc:date>2005-05-30T08:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505225#M557701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;on 192.168.1.4 could you show&lt;/P&gt;&lt;P&gt;"ipconfig /all"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 09:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505225#M557701</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-05-30T09:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505226#M557702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeric,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q. On your internal exchange server have you created a CA (Certificate Authority) for SSL authentication? As traffic is reaching your outside interface of pix for port 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I presume you have the apporiate static translation setup for this traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2005 06:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505226#M557702</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2005-05-31T06:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505227#M557703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks so much for participating on this conversation. in response to your querry, yes... I already created a CA for SSL authentication. just wondering why it is not working.. internally its ok the Outlook web access is working.. however those external user can not access it.. I have a good static translation created for my mail server and the public ip address i used is pingable over the internet..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to figure this out by checking microsoft website what else ports needed to be open.. but to date still couldnt find it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help on resolving this is greately appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jeric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2005 11:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505227#M557703</guid>
      <dc:creator>jeric_saldua</dc:creator>
      <dc:date>2005-05-31T11:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505228#M557704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeric,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK, can you post to me your full pix config (take out any sensitive info), either here or to: &lt;A href="mailto:jmia@ohgroup.co.uk"&gt;jmia@ohgroup.co.uk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll take a closer look at it for you, I only deployed OWA for a customer of mine only last week using SSL via pix on port 443 and it is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2005 12:05:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505228#M557704</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2005-05-31T12:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505229#M557705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls find below config for your kind review.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope you could help me resolve it.. i also send you a copy thru email.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;looking forward to hear from you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;jeric&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(1)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;hostname InternetDoor&lt;/P&gt;&lt;P&gt;domain-name myCompany&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol ils 389&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list OUTGOING permit tcp any host 2xx.1xx.xxx.xx1 eq smtp &lt;/P&gt;&lt;P&gt;access-list OUTGOING permit tcp any host 2xx.1xx.xxx.xx1 eq pop3 &lt;/P&gt;&lt;P&gt;access-list 101 permit ip 172.xxx.1.0 255.255.255.0 172.xxx.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Vpn_mapping permit ip any 172.xxx.2.0 255.255.255.128 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;ip address outside XXX.XXX.XXX.XXX 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address inside 172.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface inside&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;ip local pool VPN_POOL XXX.XXX.XX.X-XXX.XXX.XX.X&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 101&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface smtp 192.168.1.4 smtp netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface pop3 192.168.1.4 pop3 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;access-group OUTGOING in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 203.125.100.245 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;aaa-server mycompany protocol radius &lt;/P&gt;&lt;P&gt;aaa-server mycompany (inside) host 1xx.xxx.xxx.xxx mycompany timeout 10&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec&lt;/P&gt;&lt;P&gt;auth-prompt accept Welcome to my world !! &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set MYSET esp-aes-256 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map DYNMAP 10 set transform-set MYSET&lt;/P&gt;&lt;P&gt;crypto dynamic-map DYNMAP 30 match address Vpn_mapping&lt;/P&gt;&lt;P&gt;crypto dynamic-map DYNMAP 30 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto map MYMAP 10 ipsec-isakmp dynamic DYNMAP&lt;/P&gt;&lt;P&gt;crypto map MYMAP client configuration address initiate&lt;/P&gt;&lt;P&gt;crypto map MYMAP client configuration address respond&lt;/P&gt;&lt;P&gt;crypto map MYMAP client authentication mycompany&lt;/P&gt;&lt;P&gt;crypto map MYMAP interface outside&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;/P&gt;&lt;P&gt;isakmp key ******** address 172.xxx.x.x netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;isakmp identity address&lt;/P&gt;&lt;P&gt;isakmp nat-traversal 20&lt;/P&gt;&lt;P&gt;isakmp policy 10 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 10 encryption aes-256&lt;/P&gt;&lt;P&gt;isakmp policy 10 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 10 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 10 lifetime 86400&lt;/P&gt;&lt;P&gt;isakmp policy 30 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 30 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 30 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 30 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 30 lifetime 86400&lt;/P&gt;&lt;P&gt;vpngroup mycompany_VPN address-pool VPN_POOL&lt;/P&gt;&lt;P&gt;vpngroup mycompany_VPN dns-server 1xx.xxx.xxx.xxx xxx.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;vpngroup mycompany_VPN default-domain myCompany.com&lt;/P&gt;&lt;P&gt;vpngroup mycompany_VPN split-tunnel 101&lt;/P&gt;&lt;P&gt;vpngroup mycompany_VPN idle-time 1800&lt;/P&gt;&lt;P&gt;vpngroup mycompany_VPN password ********&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;username xxx password xxxx&lt;/P&gt;&lt;P&gt;privilege 15&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxxxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2005 14:10:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505229#M557705</guid>
      <dc:creator>jeric_saldua</dc:creator>
      <dc:date>2005-05-31T14:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505230#M557706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry, but i really do not understand you.&lt;/P&gt;&lt;P&gt;Where are the commands I asked you to add to configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTGOING permit tcp any host 2xx.1xx.xxx.xx6 eq 443 &lt;/P&gt;&lt;P&gt;ip address outside 2xx.1xx.xxx.xx6 255.255.255.252 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 443 192.168.1.4 443 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;access-group OUTGOING in interface outside &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2005 16:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505230#M557706</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-05-31T16:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook web access over pix firewall</title>
      <link>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505231#M557707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My apology I post the old config, Its already "in" after you ask me to put it in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I intentionally put the old config so you can take a look on it to verify what else is missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But each entry you asked me to key in is already there. yet it is still not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope you could help me find ways on fixing it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again for your help I really appreciate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jeric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2005 21:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outlook-web-access-over-pix-firewall/m-p/505231#M557707</guid>
      <dc:creator>jeric_saldua</dc:creator>
      <dc:date>2005-05-31T21:44:53Z</dc:date>
    </item>
  </channel>
</rss>

