<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX 501 problems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235942#M594183</link>
    <description>&lt;P&gt;Trying to install a 501 on a small business network that is hosted by another company. They currently have it set up with 172.17.xxx.xxx for their internal LAN and have it routed(?) to be 216.201.xxx.xxx on the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set the inside address to the LAN gateway and the outside interface to the public router IP? correct?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:16:31 GMT</pubDate>
    <dc:creator>admin_2</dc:creator>
    <dc:date>2020-02-21T07:16:31Z</dc:date>
    <item>
      <title>PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235942#M594183</link>
      <description>&lt;P&gt;Trying to install a 501 on a small business network that is hosted by another company. They currently have it set up with 172.17.xxx.xxx for their internal LAN and have it routed(?) to be 216.201.xxx.xxx on the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set the inside address to the LAN gateway and the outside interface to the public router IP? correct?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:16:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235942#M594183</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2020-02-21T07:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235943#M594185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   randy&lt;/P&gt;&lt;P&gt;          the inside IP shall be the LAN PCs gateway and if u have a  router after the outside interface , the interface ip of the router connecting to your outside interface will be your Next Hop address, for static routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shukky &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Mar 2004 15:37:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235943#M594185</guid>
      <dc:creator>gopal_voip</dc:creator>
      <dc:date>2004-03-04T15:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235944#M594188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How do I add the DNS servers to the equation. it looks like it either cannot find them or cannot get them through the firewall ??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Mar 2004 16:31:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235944#M594188</guid>
      <dc:creator />
      <dc:date>2004-03-04T16:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235945#M594190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list acl_inside permit udp any any eq 53 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where acl_inside is the access list on the LAN side of the pix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Mar 2004 17:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235945#M594190</guid>
      <dc:creator>patrick.cannon</dc:creator>
      <dc:date>2004-03-04T17:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235946#M594191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, i am TOTALLY clueless now. Nothing is working right, so I must be doing something terribly wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I DO NOT have access to the router configurations upstream of me, or of the router within our LAN, all I have is a sheet of paper with this info.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Local Area Network IP   172.17.2.0  255.255.255.0&lt;/P&gt;&lt;P&gt;Ethernet/Gatway IP      172.17.2.1&lt;/P&gt;&lt;P&gt;Usable IP range         172.17.2.2-172.17.2.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PUBLIC ip addresses&lt;/P&gt;&lt;P&gt;Network IP           216.201.xxx.32  255.255.255.248&lt;/P&gt;&lt;P&gt;Router Public IP     216.201.xxx.33&lt;/P&gt;&lt;P&gt;Usable IPs           216.201.xxx.34-38&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Domain Name Servers &lt;/P&gt;&lt;P&gt;66.196.216.10&lt;/P&gt;&lt;P&gt;66.196.212.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my PIX setup...what have I done wrong ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(1) &lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;enable password xxxx&lt;/P&gt;&lt;P&gt;passwd xxxx&lt;/P&gt;&lt;P&gt;hostname pixfirewall&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol ils 389&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list acl permit udp any any eq domain                &lt;/P&gt;&lt;P&gt;access-list acl permit tcp any any &lt;/P&gt;&lt;P&gt;access-list acl permit ip any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside 216.201.xxx.33 255.255.255.248&lt;/P&gt;&lt;P&gt;ip address inside 172.17.2.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 216.201.xxx.34-216.201.xxx.38 netmask 255.255.255.248&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;access-group acl in interface inside&lt;/P&gt;&lt;P&gt;conduit permit tcp any any &lt;/P&gt;&lt;P&gt;conduit permit icmp any any &lt;/P&gt;&lt;P&gt;conduit permit ip any any &lt;/P&gt;&lt;P&gt;conduit permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 216.201.xxx.33 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00 timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet 172.17.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd dns 66.196.216.10 &lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Mar 2004 18:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235946#M594191</guid>
      <dc:creator />
      <dc:date>2004-03-04T18:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235947#M594192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see 1 major problem. The PIX outside interface is 216.201.xxx.33 and you have a default route of "route outside 0.0.0.0 0.0.0.0 216.201.xxx.33 1".  This will not work because it is the same interface of the PIX.  The default route should point to the device connected on the other end of the outside interface of the PIX, for example the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 216.201.xxx.32 1  should be the PIX's default route to its next hop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't need the dhcpd dns 66.196.216.10 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And these statements are basically opening up this firewall:&lt;/P&gt;&lt;P&gt;access-list acl permit udp any any eq domain &lt;/P&gt;&lt;P&gt;access-list acl permit tcp any any &lt;/P&gt;&lt;P&gt;access-list acl permit ip any any &lt;/P&gt;&lt;P&gt;access-group acl in interface inside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is allowed as soon as you apply the basic commands.. NAT, GLOBAL etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conduit permit tcp any any &lt;/P&gt;&lt;P&gt;conduit permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are opening up the pix to the world.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default configuration of the PIX firewall is NOTHING IN AND NOTHING OUT.  You allow inside connections thru the PIX with the NAT, GLOBAL, IP Adderss, Interface Auto etc... But the permit statements you have is allowing all IP all TCP traffic from the outside to the inside networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know if this helps.  I'll watch for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Curt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Mar 2004 23:59:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235947#M594192</guid>
      <dc:creator>cgregg</dc:creator>
      <dc:date>2004-03-04T23:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235948#M594193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Should the PIX's outside interface be THE SAME AS the router ip which the PIX is connected to ????&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Mar 2004 16:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235948#M594193</guid>
      <dc:creator />
      <dc:date>2004-03-09T16:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235949#M594198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Randy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the attached document. I have setup the config with your provided IP addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this sorts out your problem, I also included on the config SMTP mail access as well, thats if you require it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how you get on - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards - Jay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Mar 2004 17:25:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235949#M594198</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2004-03-09T17:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235950#M594199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, I am trying it now &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Mar 2004 17:37:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235950#M594199</guid>
      <dc:creator />
      <dc:date>2004-03-09T17:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235951#M594200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We got it working! Thanks. We also had to have the ISP provider remove NAT from the router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Mar 2004 19:31:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235951#M594200</guid>
      <dc:creator />
      <dc:date>2004-03-09T19:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235952#M594201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Randy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am glad that it worked, can you please rate the post, as this will help others who may be experiencing the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks - Jay.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Mar 2004 08:12:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-problems/m-p/235952#M594201</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2004-03-10T08:12:45Z</dc:date>
    </item>
  </channel>
</rss>

