<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic two questions w/ PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/two-questions-w-pix/m-p/310004#M593704</link>
    <description>&lt;P&gt;A client has their primary DNS on the inside and a secondary DNS on the outside (not a DMZ port).  They want to be able to have the secondary DNS poll the primary every fifteen and intiate a zone transfer if required.  What is an easy way to do this?  The pix is running 6.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second question.  Same client wants me to restrict outbound smtp to a certain address (a mail relay located on the outside).  Can this be done?  That is, only allow outbound smtp to a specific ip...if the mail is destined for any other ip, drop it.  They do not want any inbound smtp.  Can this even be done on the PIX?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:18:49 GMT</pubDate>
    <dc:creator>admin_2</dc:creator>
    <dc:date>2020-02-21T07:18:49Z</dc:date>
    <item>
      <title>two questions w/ PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-questions-w-pix/m-p/310004#M593704</link>
      <description>&lt;P&gt;A client has their primary DNS on the inside and a secondary DNS on the outside (not a DMZ port).  They want to be able to have the secondary DNS poll the primary every fifteen and intiate a zone transfer if required.  What is an easy way to do this?  The pix is running 6.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second question.  Same client wants me to restrict outbound smtp to a certain address (a mail relay located on the outside).  Can this be done?  That is, only allow outbound smtp to a specific ip...if the mail is destined for any other ip, drop it.  They do not want any inbound smtp.  Can this even be done on the PIX?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:18:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-questions-w-pix/m-p/310004#M593704</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2020-02-21T07:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: two questions w/ PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-questions-w-pix/m-p/310005#M593707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I solved my second question.  Can someone verify this ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit tcp a.b.c.d 0.0.0.0 eq 25 w.x.y.z 0.0.0.0 eq 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a.b.c.d is the inside network and the other the outside.  I think that applied in on the inside interface will do it.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Mar 2004 19:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-questions-w-pix/m-p/310005#M593707</guid>
      <dc:creator />
      <dc:date>2004-03-26T19:12:04Z</dc:date>
    </item>
  </channel>
</rss>

