<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enabling comms (pix to pix) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/enabling-comms-pix-to-pix/m-p/306240#M562704</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your side is fine although you can modify your ACL for your Nat 0 ACL statement to this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out permit ip host 172.16.25.115 host 172.16.25.250&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(the Nat 0 ACL does not take into account port information for the translation).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An xlate and permission need to be granted on PIX B (assuming e2 is a lower security interface than the inside interface).  Something like this would work:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,e2) 172.16.25.250 172.16.25.250&lt;/P&gt;&lt;P&gt;access-list in_e2 permit tcp host 172.16.25.115 host 172.16.25.250 eq 3182&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 Aug 2004 15:16:07 GMT</pubDate>
    <dc:creator>scoclayton</dc:creator>
    <dc:date>2004-08-31T15:16:07Z</dc:date>
    <item>
      <title>Enabling comms (pix to pix)</title>
      <link>https://community.cisco.com/t5/network-security/enabling-comms-pix-to-pix/m-p/306239#M562703</link>
      <description>&lt;P&gt;Wondering if you could shed some light on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix A&lt;/P&gt;&lt;P&gt;interface inside 172.16.25.1 255.255.255.128 sec 100&lt;/P&gt;&lt;P&gt;interface e2 10.1.1.1 255.255.255.224 sec 15&lt;/P&gt;&lt;P&gt;host A 172.16.25.115 (in interface inside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix B&lt;/P&gt;&lt;P&gt;interface e2 10.1.1.2 255.255.x.x sec 10&lt;/P&gt;&lt;P&gt;host B 172.16.25.250&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both Pix are connected via e2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to get my host A to host B via another dept's pix.The communication is only set for one way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what i have done&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp host 172.16.25.115 host 172.16.25.250 eq 3182&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list acl_out &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there more i need to do?Also,given the fact that i will not configure PIX B.Is there something more that i need to allow over at PIX B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(kindly refer to diagram )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:36:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-comms-pix-to-pix/m-p/306239#M562703</guid>
      <dc:creator>echelon360</dc:creator>
      <dc:date>2020-02-21T07:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling comms (pix to pix)</title>
      <link>https://community.cisco.com/t5/network-security/enabling-comms-pix-to-pix/m-p/306240#M562704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your side is fine although you can modify your ACL for your Nat 0 ACL statement to this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out permit ip host 172.16.25.115 host 172.16.25.250&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(the Nat 0 ACL does not take into account port information for the translation).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An xlate and permission need to be granted on PIX B (assuming e2 is a lower security interface than the inside interface).  Something like this would work:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,e2) 172.16.25.250 172.16.25.250&lt;/P&gt;&lt;P&gt;access-list in_e2 permit tcp host 172.16.25.115 host 172.16.25.250 eq 3182&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Aug 2004 15:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-comms-pix-to-pix/m-p/306240#M562704</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2004-08-31T15:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling comms (pix to pix)</title>
      <link>https://community.cisco.com/t5/network-security/enabling-comms-pix-to-pix/m-p/306241#M562706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks once again for the info.Just need further clarification to this.I read that that port information is not taken into account.Does this mean that all ports belonging to 172.16.25.115 are ignored or all ports belonging to 172.16.25.115 will be allowed to pass through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct me if necessary,in the event that i need to connect 172.16.25.115 to 172.16.25.250 using port 3182,it won't go through?(i.e i'll have to go back to static/acl)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks once again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Sep 2004 23:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-comms-pix-to-pix/m-p/306241#M562706</guid>
      <dc:creator>echelon360</dc:creator>
      <dc:date>2004-09-05T23:45:20Z</dc:date>
    </item>
  </channel>
</rss>

