<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX-501 NAT/ACL Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615489#M567966</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;PIX# sh access-list&lt;BR /&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 256)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alert-interval 300&lt;BR /&gt;access-list WEB; 2 elements&lt;BR /&gt;access-list WEB line 1 permit tcp any any (hitcnt=23)&lt;BR /&gt;access-list WEB line 2 permit udp any any (hitcnt=578)&lt;BR /&gt;PIX# sh static&lt;BR /&gt;static (inside,outside) tcp &lt;OUTSIDE ip=""&gt; www 192.168.2.1 www netmask 255.255.255.255 0 0&lt;/OUTSIDE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Feb 2011 17:53:04 GMT</pubDate>
    <dc:creator>kooper390</dc:creator>
    <dc:date>2011-02-03T17:53:04Z</dc:date>
    <item>
      <title>PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615480#M567957</link>
      <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Problem is, that in a remote location is a FAX-SIP-Adapter with his factory default address 192.168.2.1. I need to configure this device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the remote network has the address range 192.168.170.0/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, I tried to change the intern interface to the 192.168.2.0/24 network.&lt;/P&gt;&lt;P&gt;Ok everything is fine and I can ping the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I set some ACL and NAT rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list WEB permit tcp any any&lt;BR /&gt;access-list WEB permit udp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group WEB in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 170.230.30.18 www 192.168.2.1 www netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my config so far. But I get noch access to the webfrontend of the adapter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I used a SIP-Telefon webfrontend in the origin network (192.168.170.0/24), I get access from outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any thing to consider?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have here a PiX 501 with 6.3&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:44:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615480#M567957</guid>
      <dc:creator>kooper390</dc:creator>
      <dc:date>2019-03-11T19:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615481#M567958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the configuration that you mentioned you should be able to reach 192.168.2.1 on port 80 from outside by sending traffic to 170.230.30.18 on port 80.&lt;/P&gt;&lt;P&gt;You can confirm that the traffic is getting to the PIX by checking the hitcounts on the ACL &lt;STRONG&gt;show access-list WEB&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the IP 170.230.30.18 is not the outside IP of the PIX and is not being used anywhere else, you can change the static command for this one:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,outside) 170.230.30.18 192.168.2.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probably the problem is that you need to get traffic on other ports besides port 80 to the SIP device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 13:28:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615481#M567958</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-02-03T13:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615482#M567959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only for the initial configuration of the adapter I need access. Now I cannot test because they are working there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I access the PIX further when I set &lt;STRONG&gt;static (inside,outside) 170.230.30.18 192.168.2.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I can only access the PIX from outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kind regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 13:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615482#M567959</guid>
      <dc:creator>kooper390</dc:creator>
      <dc:date>2011-02-03T13:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615483#M567960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gerit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you add &lt;STRONG&gt;static (inside,outside) 170.230.30.18 192.168.2.1&lt;STRONG&gt; and 170.230.30.18 &lt;/STRONG&gt;&lt;/STRONG&gt;and 170.230.30.18 happens to be the outside IP of the PIX then you will lose access to the PIX. If the IP is used on other static rules, you might break those rules. Otherwise, there's no problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 13:46:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615483#M567960</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-02-03T13:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615484#M567961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok the ACL work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX# show access-list WEB&lt;BR /&gt;access-list WEB; 2 elements&lt;BR /&gt;access-list WEB line 1 permit tcp any any (hitcnt=10)&lt;BR /&gt;access-list WEB line 2 permit udp any any (hitcnt=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but I get no access to the web interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 16:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615484#M567961</guid>
      <dc:creator>kooper390</dc:creator>
      <dc:date>2011-02-03T16:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615485#M567962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Almost for sure the web traffic is being sent to the server.&lt;/P&gt;&lt;P&gt;Can you confirm the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. If you log into the server, can you open a browser and get to the Internet? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm pretty sure that web traffic is being sent by the PIX to the server, so let's make sure the server is receiving it and replying back with the web page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 17:31:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615485#M567962</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-02-03T17:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615486#M567963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hm and theres the problem.&lt;/P&gt;&lt;P&gt;In this net I have no other device for checking.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 17:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615486#M567963</guid>
      <dc:creator>kooper390</dc:creator>
      <dc:date>2011-02-03T17:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615487#M567964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PIX#sh local-host&lt;/P&gt;&lt;P&gt;Interface inside: 5 active, 8 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;local host: &amp;lt;192.168.2.1&amp;gt;,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP connection count/limit = 1/unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count = 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP connection count/limit = 0/unlimited&lt;BR /&gt;&amp;nbsp; AAA:&lt;BR /&gt;&amp;nbsp; Xlate(s):&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PAT Global &lt;OUTSIDE ip=""&gt;(80) Local 192.168.2.1(80)&lt;BR /&gt;&amp;nbsp; Conn(s):&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP out &lt;MY ip=""&gt;:18790 in 192.168.2.1:80 idle 0:00:55 Bytes 0 flags SaAB&lt;/MY&gt;&lt;/OUTSIDE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 17:48:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615487#M567964</guid>
      <dc:creator>kooper390</dc:creator>
      <dc:date>2011-02-03T17:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615488#M567965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gerit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's take it from here to try to fix the problem.&lt;/P&gt;&lt;P&gt;Please post the output of the ACL and static as you currently have it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 17:50:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615488#M567965</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-02-03T17:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615489#M567966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;PIX# sh access-list&lt;BR /&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 256)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alert-interval 300&lt;BR /&gt;access-list WEB; 2 elements&lt;BR /&gt;access-list WEB line 1 permit tcp any any (hitcnt=23)&lt;BR /&gt;access-list WEB line 2 permit udp any any (hitcnt=578)&lt;BR /&gt;PIX# sh static&lt;BR /&gt;static (inside,outside) tcp &lt;OUTSIDE ip=""&gt; www 192.168.2.1 www netmask 255.255.255.255 0 0&lt;/OUTSIDE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 17:53:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615489#M567966</guid>
      <dc:creator>kooper390</dc:creator>
      <dc:date>2011-02-03T17:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615490#M567967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;and when I scan the outside (nmap) I get only 22 as open&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 17:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615490#M567967</guid>
      <dc:creator>kooper390</dc:creator>
      <dc:date>2011-02-03T17:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: PIX-501 NAT/ACL Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615491#M567968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The adapter have no default GW ... ahm ... embarrassing ... so it could never work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for support!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gerit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 15:23:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-nat-acl-problem/m-p/1615491#M567968</guid>
      <dc:creator>kooper390</dc:creator>
      <dc:date>2011-02-04T15:23:21Z</dc:date>
    </item>
  </channel>
</rss>

