<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix/m-p/307124#M594352</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This error is logged when you have a deny ACL statement applied to the relevant interface i.e. your outside interface, check your ACL's that are applied on the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks - Jay &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Feb 2004 16:07:55 GMT</pubDate>
    <dc:creator>jmia</dc:creator>
    <dc:date>2004-02-24T16:07:55Z</dc:date>
    <item>
      <title>PIX</title>
      <link>https://community.cisco.com/t5/network-security/pix/m-p/307123#M594351</link>
      <description>&lt;P&gt;Hi ppl,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to ftp from a LAN behind a firewall to our HQ which is running a PIX 5.1. We have created an acl to allow my source ip (1.1.1.1)to the ftp server (2.2.2.2). But i got connection timed out. My syslog only shown the following &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;87&amp;gt;Feb 22 2004 12:32:46: %PIX-4-106019: IP packet from 1.1.1.1 to 2.2.2.2, protocol 17 received from interface "outside" deny by access-group "ACL_in"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that protocol 17 is used by UDP, but what cause my ftp to become a UDP protocol? fixup protocol 21 was configured. Could NAT or PAT causes the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;advises needed, thank you!&lt;/P&gt;&lt;P&gt;    &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix/m-p/307123#M594351</guid>
      <dc:creator>jkh_tt</dc:creator>
      <dc:date>2020-02-21T07:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: PIX</title>
      <link>https://community.cisco.com/t5/network-security/pix/m-p/307124#M594352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This error is logged when you have a deny ACL statement applied to the relevant interface i.e. your outside interface, check your ACL's that are applied on the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks - Jay &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2004 16:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix/m-p/307124#M594352</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2004-02-24T16:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: PIX</title>
      <link>https://community.cisco.com/t5/network-security/pix/m-p/307125#M594353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Jay, our ACL only allow port 80 and ftp. BUt not UDP. My query is that i was connecting using ftp from one site behind a firewall to our HQ which is running PIX. BUt on the PIX syslog, the only traffic that i can see from this source address to the ftp server is only protocol 17 (UDP) instead of what i am expecting (ftp 21)? Will NAT or PAT cause the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THanks!!! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2004 02:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix/m-p/307125#M594353</guid>
      <dc:creator>jkh_tt</dc:creator>
      <dc:date>2004-02-25T02:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: PIX</title>
      <link>https://community.cisco.com/t5/network-security/pix/m-p/307126#M594354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Pls check this things&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Do have any acl applied on inside interface(for testing)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Apply the acl u used as on outside interface direction out in acl group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) telnet 2.2.2.2 21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Feb 2004 02:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix/m-p/307126#M594354</guid>
      <dc:creator>sateeshk</dc:creator>
      <dc:date>2004-02-27T02:23:25Z</dc:date>
    </item>
  </channel>
</rss>

