<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to open a RTP port range 50000 to 60000 in PIX Firewall 515 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719715#M562044</link>
    <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got a request to open up port on firewall for three hosts externally accessing. I am new to the security. Please help me in configruing the ports on firewall 515 cisco PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is the exmple of one host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 1) ---- video1.xx.com ---&amp;gt; 10.1.1.1 ------ internal ports TCP/UDP (5060/6060), RTP (50000-60000) TCP8080&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----&amp;gt; 63.200.215.50&amp;nbsp; ------- External ports TCP/UDP (5060/6060), RTP (50000-60000) TCP8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought of these following step:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside)&amp;nbsp; 63.200.215.50 10.1.1.1 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 63.200.215.50 eq 4060&lt;/P&gt;&lt;P&gt;access-list outside permit udp any host 63.200.215.50 eq 4060&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 63.200.215.50 eq 5060&lt;/P&gt;&lt;P&gt;access-list outside permit udp any host 63.200.215.50 eq 5060&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 63.200.215.50 eq 8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;Can someone validate the above config, whether this will work and moreover i want to know how to give the range for protocol RTP (50000-60000).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will the fixup protocol can do something with RTP range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I am seeing the fixup protocol in PIX is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw01# sh fixup&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 4096&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol ils 389&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;no fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help or guide would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ahmed&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:35:45 GMT</pubDate>
    <dc:creator>habeebuddin786</dc:creator>
    <dc:date>2019-03-11T20:35:45Z</dc:date>
    <item>
      <title>How to open a RTP port range 50000 to 60000 in PIX Firewall 515</title>
      <link>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719715#M562044</link>
      <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got a request to open up port on firewall for three hosts externally accessing. I am new to the security. Please help me in configruing the ports on firewall 515 cisco PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is the exmple of one host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 1) ---- video1.xx.com ---&amp;gt; 10.1.1.1 ------ internal ports TCP/UDP (5060/6060), RTP (50000-60000) TCP8080&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----&amp;gt; 63.200.215.50&amp;nbsp; ------- External ports TCP/UDP (5060/6060), RTP (50000-60000) TCP8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought of these following step:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside)&amp;nbsp; 63.200.215.50 10.1.1.1 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 63.200.215.50 eq 4060&lt;/P&gt;&lt;P&gt;access-list outside permit udp any host 63.200.215.50 eq 4060&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 63.200.215.50 eq 5060&lt;/P&gt;&lt;P&gt;access-list outside permit udp any host 63.200.215.50 eq 5060&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 63.200.215.50 eq 8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;Can someone validate the above config, whether this will work and moreover i want to know how to give the range for protocol RTP (50000-60000).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will the fixup protocol can do something with RTP range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I am seeing the fixup protocol in PIX is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw01# sh fixup&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 4096&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol ils 389&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;no fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help or guide would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ahmed&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:35:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719715#M562044</guid>
      <dc:creator>habeebuddin786</dc:creator>
      <dc:date>2019-03-11T20:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to open a RTP port range 50000 to 60000 in PIX Firewall</title>
      <link>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719716#M562046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Habeeb,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config looks fine, but not sure what zPIX software version are using. Nevertheless here is a config guides, kindly select yours and you can check whether it has teh range option after the ACL command, because this command depends on the version of software that you use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/customer/products/sw/secursw/ps2120/prod_command_reference_list.html"&gt;http://www.cisco.com/en/US/customer/products/sw/secursw/ps2120/prod_command_reference_list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 18:55:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719716#M562046</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-19T18:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to open a RTP port range 50000 to 60000 in PIX Firewall</title>
      <link>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719717#M562052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your quick help.&lt;/P&gt;&lt;P&gt;The software version using on the PIX is 6.3(5)114.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked through the given link on 6.3 version, but unable to find the range to give the rtp ports in ACL rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even tried to give Fixup protocol rtp 50000-60000, getting error as bad protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is any other way you can suggest?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;-Ahmed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 19:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719717#M562052</guid>
      <dc:creator>habeebuddin786</dc:creator>
      <dc:date>2011-05-19T19:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to open a RTP port range 50000 to 60000 in PIX Firewall</title>
      <link>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719718#M562054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Habib,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did check the comand ref again and in PIX 6.3 you do have the range option in ACL:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/customer/docs/security/pix/pix63/command/reference/ab.html#wp1067755"&gt;http://www.cisco.com/en/US/customer/docs/security/pix/pix63/command/reference/ab.html#wp1067755&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The synatxt would be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test extended permit ip any any range 50000 60000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 19:19:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719718#M562054</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-19T19:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to open a RTP port range 50000 to 60000 in PIX Firewall</title>
      <link>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719719#M562057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the Application for SIP is RFC compliant, you shouldnt need to open those ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 19:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-open-a-rtp-port-range-50000-to-60000-in-pix-firewall-515/m-p/1719719#M562057</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-19T19:51:50Z</dc:date>
    </item>
  </channel>
</rss>

