<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: permitting traffic through pix 501 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148548#M580324</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;use netblocks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.10.100 255.255.255.252 (covers 192.168.10.100 through 103)&lt;/P&gt;&lt;P&gt;192.168.10.104 255.255.255.248 (covers 192.168.10.104 through 111)&lt;/P&gt;&lt;P&gt;192.168.10.112 255.255.255.240 (covers 192.168.10.112 through 127)&lt;/P&gt;&lt;P&gt;192.168.10.128 255.255.255.224 (covers 192.168.10.128 through 159)&lt;/P&gt;&lt;P&gt;192.168.10.160 255.255.255.240 (covers 192.168.10.160 through 175)&lt;/P&gt;&lt;P&gt;192.168.10.176 255.255.255.252 (covers 192.168.10.176 though 179)&lt;/P&gt;&lt;P&gt;192.168.10.180 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those statements will cover all of your ip address space for your servers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Sep 2003 11:43:45 GMT</pubDate>
    <dc:creator>mostiguy</dc:creator>
    <dc:date>2003-09-17T11:43:45Z</dc:date>
    <item>
      <title>permitting traffic through pix 501</title>
      <link>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148545#M580306</link>
      <description>&lt;P&gt;I have a class c network. 192.168.1.0 /24&lt;/P&gt;&lt;P&gt;i have several web,ftp and mail server 192.168.1.100 - 180&lt;/P&gt;&lt;P&gt;I also have two dns server 192.168.1.35,192.168.1.45&lt;/P&gt;&lt;P&gt;the problem is that i need to allow traffic from the outside to these webservers each host is a different server.  how do i do this without having to enter the different static and access-list commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for example&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.0.0.100 192.168.1.100 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list in permit tcp any host 10.0.0.100 eq www&lt;/P&gt;&lt;P&gt;access-list in permit tcp any host 10.0.0.100 eq smtp&lt;/P&gt;&lt;P&gt;access-list in permit tcp any host 10.0.0.100 eq ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i do not want to do this for 255 address that would be crazy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:59:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148545#M580306</guid>
      <dc:creator>jcajuste</dc:creator>
      <dc:date>2020-02-21T06:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: permitting traffic through pix 501</title>
      <link>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148546#M580311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You prety much do have to do it for all addresses, but it's easier of you can group them together.  If you need to do it for all 255 addresses then it's easy, just do:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.0.0.0 192.168.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list in permit tcp any host 10.0.0.0 eq www&lt;/P&gt;&lt;P&gt;access-list in permit tcp any host 10.0.0.0 eq smtp&lt;/P&gt;&lt;P&gt;access-list in permit tcp any host 10.0.0.0 eq ftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you only need to do it for 100-180 then it gets a little more difficult, as you have to group these together but with subnet masking it gets difficult.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I would recommend using an object group for the protocols in the access-list as follows:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;objet-group service &lt;I&gt;allowed_prots&lt;/I&gt; tcp&lt;/P&gt;&lt;P&gt;   port-object eq ftp&lt;/P&gt;&lt;P&gt;   port-object eq www&lt;/P&gt;&lt;P&gt;   port-object eq smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list in permit tcp any host x.x.x.x object-group &lt;I&gt;allowed_prots&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This'll save two access-list lines per host.  See &lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/707/pix_obj_grp.html" target="_blank"&gt;http://www.cisco.com/warp/public/707/pix_obj_grp.html&lt;/A&gt; for details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2003 04:18:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148546#M580311</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-09-17T04:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: permitting traffic through pix 501</title>
      <link>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148547#M580318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the object gorup. but i still have to do for each address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2003 10:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148547#M580318</guid>
      <dc:creator>jcajuste</dc:creator>
      <dc:date>2003-09-17T10:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: permitting traffic through pix 501</title>
      <link>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148548#M580324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;use netblocks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.10.100 255.255.255.252 (covers 192.168.10.100 through 103)&lt;/P&gt;&lt;P&gt;192.168.10.104 255.255.255.248 (covers 192.168.10.104 through 111)&lt;/P&gt;&lt;P&gt;192.168.10.112 255.255.255.240 (covers 192.168.10.112 through 127)&lt;/P&gt;&lt;P&gt;192.168.10.128 255.255.255.224 (covers 192.168.10.128 through 159)&lt;/P&gt;&lt;P&gt;192.168.10.160 255.255.255.240 (covers 192.168.10.160 through 175)&lt;/P&gt;&lt;P&gt;192.168.10.176 255.255.255.252 (covers 192.168.10.176 though 179)&lt;/P&gt;&lt;P&gt;192.168.10.180 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those statements will cover all of your ip address space for your servers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2003 11:43:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148548#M580324</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2003-09-17T11:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: permitting traffic through pix 501</title>
      <link>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148549#M580330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you, but forgive me for not being so bright.&lt;/P&gt;&lt;P&gt;will the pix know to translate 10.0.0.100 to 192.168.10.100. ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2003 14:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permitting-traffic-through-pix-501/m-p/148549#M580330</guid>
      <dc:creator>jcajuste</dc:creator>
      <dc:date>2003-09-17T14:31:07Z</dc:date>
    </item>
  </channel>
</rss>

