<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX weired problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226974#M588732</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You seem to be running an old version of software on your pix, this problem could be bug related. I would try and upgrade your pix to a more recent version (try 6.3(3) or 6.2(3))and see of the problem still exists&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Oct 2003 11:41:15 GMT</pubDate>
    <dc:creator>p.mcgowan</dc:creator>
    <dc:date>2003-10-16T11:41:15Z</dc:date>
    <item>
      <title>PIX weired problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226969#M588724</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i have a PIX 520 running softwrae 5.1(4) , i have created a static translation in order to allow outside users access a server on port 443(HTTPS) .&lt;/P&gt;&lt;P&gt;This was done with the following statements:&lt;/P&gt;&lt;P&gt;-static(inside,outside) global_ip_address  private_ip_address  netmask 255.255.255.255  0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-access-list  name1  permit tcp any host global_ip eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-access-group name in interface  outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is working fine  ,&lt;/P&gt;&lt;P&gt; the problem is once a static translation is  opened  from an outside pc to that private  destination  on port 443  , i am able to initiate  from the same pc  another session  to the same destination ON ANOTHER PORT ( FOR EXAMPLE PORT 80 or 3389) ,normally the pix should not allow that .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any one could help ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:02:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226969#M588724</guid>
      <dc:creator>teltac</dc:creator>
      <dc:date>2020-02-21T07:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: PIX weired problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226970#M588725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are right this should never be the case.&lt;/P&gt;&lt;P&gt;How about any other permit entries in access-list name1? May be you missed them out!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2003 18:29:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226970#M588725</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2003-10-14T18:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: PIX weired problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226971#M588726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nadeem,&lt;/P&gt;&lt;P&gt;Thanks for your reply ,&lt;/P&gt;&lt;P&gt; there are  no other entries in the access list name1 , should i add  &lt;/P&gt;&lt;P&gt;access-list  name1 deny any any &lt;/P&gt;&lt;P&gt;or it is added by default at the end of each access list? may be is it  a software bug ?&lt;/P&gt;&lt;P&gt;help is needed&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2003 05:05:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226971#M588726</guid>
      <dc:creator>teltac</dc:creator>
      <dc:date>2003-10-15T05:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: PIX weired problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226972#M588728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny any any is implicitly there so no need to add.&lt;/P&gt;&lt;P&gt;Could you please confirm if you have done the "clear xlat"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2003 06:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226972#M588728</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2003-10-15T06:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: PIX weired problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226973#M588730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nadeem,&lt;/P&gt;&lt;P&gt;yes ," clear xlate" was done before and i have tried it again and still i have the same problem.&lt;/P&gt;&lt;P&gt;Note that if i try to initiate a connection on a port other that specified  in the access list it is denied by PIX ,  they are bypassed by PIX ONLY  when there s a connection already opened to the port  specified in the access list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that you get my idea ,&lt;/P&gt;&lt;P&gt;this problem   really  affects my network security because once an outside connection is opened to my mail sever , or graph server , the outside user could explore my servers on others ports !!?&lt;/P&gt;&lt;P&gt;Thanks in advance for your reply &lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jacob.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2003 09:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226973#M588730</guid>
      <dc:creator>teltac</dc:creator>
      <dc:date>2003-10-16T09:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: PIX weired problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226974#M588732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You seem to be running an old version of software on your pix, this problem could be bug related. I would try and upgrade your pix to a more recent version (try 6.3(3) or 6.2(3))and see of the problem still exists&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2003 11:41:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226974#M588732</guid>
      <dc:creator>p.mcgowan</dc:creator>
      <dc:date>2003-10-16T11:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: PIX weired problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226975#M588735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i have tried to upgrade pix  to a newer Version 6.1 , but each time  i do that, i am getting my pix reloaded by itself although it is equipped  with 128 MB RAM and 16 MB Flash so i am obliged to go back to 5.1(4) , so what can i do in such case ?&lt;/P&gt;&lt;P&gt;Note : all my real servers ( DNS , mail, www server ..) are running behind that firewall , so i can't forced down for a long time .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jacob.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Oct 2003 14:51:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226975#M588735</guid>
      <dc:creator>teltac</dc:creator>
      <dc:date>2003-10-18T14:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: PIX weired problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226976#M588736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most probably you have two Flash cards 2MB (old) + 16MB (new one). When the PIX reloads it dumps out the message of Flash card not supported or something similiar. That is why you are not able to load up 6.x code.&lt;/P&gt;&lt;P&gt;Please remove the old Flash card and upgrade the PIX.&lt;/P&gt;&lt;P&gt;Try to upgrade to 6.3.3 and not to 6.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Oct 2003 17:10:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226976#M588736</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2003-10-18T17:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX weired problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226977#M588738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using any conduits on the outside interface? Conduits and ACL's on the same interface can result in problems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Oct 2003 08:43:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-weired-problem/m-p/226977#M588738</guid>
      <dc:creator>lwierenga</dc:creator>
      <dc:date>2003-10-19T08:43:33Z</dc:date>
    </item>
  </channel>
</rss>

