<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 501 remote desktop or remote FTP? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645125#M591422</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using this as a guide (&lt;A href="https://community.cisco.com/docs/DOC-1972"&gt;https://supportforums.cisco.com/docs/DOC-1972&lt;/A&gt;), I came up with the commands below: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static(inside,outside) &lt;PIX outside="" ip=""&gt; &lt;PIX inside="" ip=""&gt; netmask 255.255.255.255&lt;/PIX&gt;&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host &lt;PIX inside="" ip=""&gt; 5900&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit udp any host &lt;PIX inside="" ip=""&gt; eq 5900&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Note: I do not have an ASA and I assume I want 5900 because I'm trying to get TightVNC to work and that's the default port for it.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would this work as I hope? If so, does it matter where it goes in the config file? And if this is correct, or after someone tweaks it a little, is there any thing else at all that I need to do to be able to VNC (or FTP) in from off-site to my and other computers on the local network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Feb 2011 16:49:00 GMT</pubDate>
    <dc:creator>mfaerber1</dc:creator>
    <dc:date>2011-02-18T16:49:00Z</dc:date>
    <item>
      <title>Pix 501 remote desktop or remote FTP?</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645122#M591412</link>
      <description>&lt;P&gt;Hello, utter novice here with a very old Sun server behind a Pix 501 (v6.3) running PDM v3.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to access the server files from a remote location but I am overwelmed trying to learn how everything works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that I need to simply either create some new rules or configure the "Easy VPN Remote" section of the PDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone please walk me through the PDM so that I can either use remote desktop or FTP from anywhere? Whichever is simpler to explain is fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:52:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645122#M591412</guid>
      <dc:creator>mfaerber1</dc:creator>
      <dc:date>2019-03-11T19:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 501 remote desktop or remote FTP?</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645123#M591415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To access the inside server remotely you can either use a VPN tunnel or simply use a NAT rule to redirect traffic to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a public IP on the outside interface of the PIX, you can simply create a Static PAT rule to redirect 3389 to the server and permit it with an ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's been years that I don't touch PDM, but I can show you the commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 20:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645123#M591415</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-02-17T20:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 501 remote desktop or remote FTP?</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645124#M591418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much Federico. I think I see all of the IPs I need in the PDM. I have not yet figured out how to edit the config file within the PDM - I can view it though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I learn how to do that, I'll try your code if you wouldn't mind. Tell me though, if it matters where in the config file I insert it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 22:56:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645124#M591418</guid>
      <dc:creator>mfaerber1</dc:creator>
      <dc:date>2011-02-17T22:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 501 remote desktop or remote FTP?</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645125#M591422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using this as a guide (&lt;A href="https://community.cisco.com/docs/DOC-1972"&gt;https://supportforums.cisco.com/docs/DOC-1972&lt;/A&gt;), I came up with the commands below: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static(inside,outside) &lt;PIX outside="" ip=""&gt; &lt;PIX inside="" ip=""&gt; netmask 255.255.255.255&lt;/PIX&gt;&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host &lt;PIX inside="" ip=""&gt; 5900&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit udp any host &lt;PIX inside="" ip=""&gt; eq 5900&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Note: I do not have an ASA and I assume I want 5900 because I'm trying to get TightVNC to work and that's the default port for it.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would this work as I hope? If so, does it matter where it goes in the config file? And if this is correct, or after someone tweaks it a little, is there any thing else at all that I need to do to be able to VNC (or FTP) in from off-site to my and other computers on the local network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 16:49:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645125#M591422</guid>
      <dc:creator>mfaerber1</dc:creator>
      <dc:date>2011-02-18T16:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 501 remote desktop or remote FTP?</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645126#M591427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;static(inside,outside) &lt;PIX outside="" ip=""&gt; &lt;PIX inside="" ip=""&gt; netmask 255.255.255.255&lt;/PIX&gt;&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host &lt;PIX inside="" ip=""&gt; 5900&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit udp any host &lt;PIX inside="" ip=""&gt; eq 5900&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above config is correct.&lt;/P&gt;&lt;P&gt;&lt;PIX outside="" ip=""&gt; is the public IP that you're going to assign to the server&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;&lt;PIX inside="" ip=""&gt; is the real inside IP of the server&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're going to use for &lt;PIX outside="" ip=""&gt; the same IP that is assigned to the PIX outside interface, you need to change the above static command for:&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;static(inside,outside) tcp &lt;PIX outside="" ip=""&gt; 5900 &lt;PIX inside="" ip=""&gt; 5900 netmask 255.255.255.255&lt;/PIX&gt;&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;static(inside,outside) udp &lt;PIX outside="" ip=""&gt; 5900 &lt;PIX inside="" ip=""&gt; 5900 netmask 255.255.255.255&lt;/PIX&gt;&lt;/PIX&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You also need to add:&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 19:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-remote-desktop-or-remote-ftp/m-p/1645126#M591427</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-02-18T19:03:34Z</dc:date>
    </item>
  </channel>
</rss>

