<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: pix https in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-https/m-p/295082#M562734</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I doubt it will work with adding fixup 443, &lt;/P&gt;&lt;P&gt;you need to collect syslog messages now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 29 Aug 2004 17:16:44 GMT</pubDate>
    <dc:creator>nkhawaja</dc:creator>
    <dc:date>2004-08-29T17:16:44Z</dc:date>
    <item>
      <title>pix https</title>
      <link>https://community.cisco.com/t5/network-security/pix-https/m-p/295077#M562722</link>
      <description>&lt;P&gt;I have pix 525 with three interfaces. All traffic flows accept for https connections, they work to the dmz.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-https/m-p/295077#M562722</guid>
      <dc:creator>wharrison</dc:creator>
      <dc:date>2020-02-21T07:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: pix https</title>
      <link>https://community.cisco.com/t5/network-security/pix-https/m-p/295078#M562726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so i get that you can't open up https sites from inside to outside? Is this a new installation? What OS version of PIX? Are there any syslog messages you can collect? is there any particular site you are having trouble with?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even my questions are longer than your description of problem &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Aug 2004 01:26:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-https/m-p/295078#M562726</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-08-27T01:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: pix https</title>
      <link>https://community.cisco.com/t5/network-security/pix-https/m-p/295079#M562729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a new installation, we have six web servers on the dmz. Two of the web servers run https. These are the two web servers that you can not access thru 443 from inside or outside. I just upgraded the OS from 6.3.1 to 6.3.4 along with the pdm 3.01 to 3.02. One server is MS Exchange OWA, the other a ssl java website page.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Aug 2004 10:29:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-https/m-p/295079#M562729</guid>
      <dc:creator>wharrison</dc:creator>
      <dc:date>2004-08-27T10:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: pix https</title>
      <link>https://community.cisco.com/t5/network-security/pix-https/m-p/295080#M562732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So was it working with 6.3.1? &lt;/P&gt;&lt;P&gt;Can you share the config (hide the IP addresses).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any syslog messages? What is the server in question IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Aug 2004 16:51:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-https/m-p/295080#M562732</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-08-27T16:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: pix https</title>
      <link>https://community.cisco.com/t5/network-security/pix-https/m-p/295081#M562733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It did not work with 6.3.1, but I wonder if adding 443 to the fixup protocol will work. please respond.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Aug 2004 14:23:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-https/m-p/295081#M562733</guid>
      <dc:creator>wharrison</dc:creator>
      <dc:date>2004-08-29T14:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: pix https</title>
      <link>https://community.cisco.com/t5/network-security/pix-https/m-p/295082#M562734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I doubt it will work with adding fixup 443, &lt;/P&gt;&lt;P&gt;you need to collect syslog messages now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Aug 2004 17:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-https/m-p/295082#M562734</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-08-29T17:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: pix https</title>
      <link>https://community.cisco.com/t5/network-security/pix-https/m-p/295083#M562735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I discovered the two web servers also have two nic cards, one connected to the dmz and the other to the lan network. I think this might be the problem please respond.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Aug 2004 17:31:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-https/m-p/295083#M562735</guid>
      <dc:creator>wharrison</dc:creator>
      <dc:date>2004-08-30T17:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: pix https</title>
      <link>https://community.cisco.com/t5/network-security/pix-https/m-p/295084#M562736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like you're confusing your servers. Each nic on the servers is configured for a different network (dmz/inside). Try removing the servers from the LAN and add the corresponding statements in your PIX to talk to the servers through the DMZ.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2004 22:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-https/m-p/295084#M562736</guid>
      <dc:creator>TimeCr0ss</dc:creator>
      <dc:date>2004-09-01T22:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: pix https</title>
      <link>https://community.cisco.com/t5/network-security/pix-https/m-p/295085#M562737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I personally do not consider this a good security practice to connect a device in DMZ directly to the internal LAN. The justification being if your DMZ server is compromised your internal devices are at a higher risk of being compromised. If the second NIC on the DMZ servers connects to some other LAN (such as a dedicated backup LAN) then my concerns do not apply to your situation and ignore them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer your actual question, when you have multiple NICs installed in a MS Windows machine the TCP/IP stack only uses one default gateway to communicate with the outside world. There is not hard and fast rule as to which gateway will be used. Do you have multiple default gateways configured?: If yes then i will recommend removing the default gateway on the NIC connected to the internal LAN thereby forcing all traffic from unknown destinations to flow through the PIX. Only communication to internal LAN hosts will flow through the secondary NIC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Sep 2004 04:48:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-https/m-p/295085#M562737</guid>
      <dc:creator>a.awan</dc:creator>
      <dc:date>2004-09-02T04:48:42Z</dc:date>
    </item>
  </channel>
</rss>

