<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX OS version 6.3(1) bug? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302813#M594393</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool.  I was out of the office for a while but I did look at the config and you should be fine.  Most people don't realize that a port static only works for packets *sourced* from that port.  So, when trying to open a web browser on the mail server where you have a port static configured will not work becuase the packets from the mail server (in this case) are not *sourced* from port 25.  You need to have a corresponding nat and global statement for the web browsing to work.  Not sure how clear this is but your config is fine.  I am guessing you may have been running into a known issue regarding statics and arp in the 6.3 code.  Glad you got it fixed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Feb 2004 18:28:27 GMT</pubDate>
    <dc:creator>scoclayton</dc:creator>
    <dc:date>2004-02-25T18:28:27Z</dc:date>
    <item>
      <title>PIX OS version 6.3(1) bug?</title>
      <link>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302806#M594378</link>
      <description>&lt;P&gt;I have been looking for a definite answer to whether there is a bug that will not allow my PIX 501 with 6.3(1) to use dynamic and static PAT at the same time.  The problem I have is this:  I'm setting up a PIX on a PPPoE dsl connection with a web server behind it.  I can get dynamic PAT to work to allow all inside hosts to access the internet.  I can get static PAT to allow outside access to the web server.  I cannot get both to work at the same time.  I am a MCSE but am new to Cisco/PIX.  &lt;/P&gt;&lt;P&gt;In reading some posts, I saw a reference to a bug that affects this.  I have seen other posts that seem to indicate I should be able to do this sucessfully.  When I had it set up, I could access the web server from the outside, but only the web server could access the internet.  Any suggestions?  I have been using the quick start instructions that came with the PIX.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:15:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302806#M594378</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2020-02-21T07:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OS version 6.3(1) bug?</title>
      <link>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302807#M594380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Should work fine, you should have the following:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 80 &lt;INTERNAL address="" of="" web="" server=""&gt; 80 netmask 255.255.255.255&lt;/INTERNAL&gt;&lt;/P&gt;&lt;P&gt;access-list inbound permit tcp any interface outside eq www&lt;/P&gt;&lt;P&gt;access-group inbound in interface outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2004 05:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302807#M594380</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2004-02-23T05:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OS version 6.3(1) bug?</title>
      <link>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302808#M594382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the exact commands in my pix and I have the exact problem. My Mail Server can recieve port 25 coming inbound but cannot get outbound at all.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2004 22:06:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302808#M594382</guid>
      <dc:creator>shane</dc:creator>
      <dc:date>2004-02-24T22:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OS version 6.3(1) bug?</title>
      <link>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302809#M594384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds to me like a common config issue seen when doing port redirection.  Can you share your config with us for review?  Remember to change public IP addresses (to something consistent please) and blank your passwords.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2004 14:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302809#M594384</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2004-02-25T14:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OS version 6.3(1) bug?</title>
      <link>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302810#M594385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the config I was testing with.  Basically the 10.0.0.2 Mail server is the one that cannot get out to the internet in this config but all other machines can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable password XXX encrypted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;passwd XXX encrypted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname pixfirewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;           &lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inbound permit icmp any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inbound permit tcp any interface outside eq smtp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside X.X.X.X 255.255.255.252&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address inside 10.0.0.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface smtp 10.0.0.2 smtp netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inbound in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;             &lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2004 15:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302810#M594385</guid>
      <dc:creator>shane</dc:creator>
      <dc:date>2004-02-25T15:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OS version 6.3(1) bug?</title>
      <link>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302811#M594388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you got any syslog messages that you can post to us please. If haven't then do the following (in config mode):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging buffer debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TRY connection="" to="" internet="" from="" 10.0.0.2="" server=""&gt;&lt;/TRY&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post the results, thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2004 15:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302811#M594388</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2004-02-25T15:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OS version 6.3(1) bug?</title>
      <link>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302812#M594391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well the wierd thing is I was booting all my test gear up to get the logs and it looks like everything is working now. Not sure if it needed a good reboot or clear xlate but I am able to access the internet from the mail server as well as recieve inbound ports......hmmmm&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2004 16:49:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302812#M594391</guid>
      <dc:creator>shane</dc:creator>
      <dc:date>2004-02-25T16:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OS version 6.3(1) bug?</title>
      <link>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302813#M594393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool.  I was out of the office for a while but I did look at the config and you should be fine.  Most people don't realize that a port static only works for packets *sourced* from that port.  So, when trying to open a web browser on the mail server where you have a port static configured will not work becuase the packets from the mail server (in this case) are not *sourced* from port 25.  You need to have a corresponding nat and global statement for the web browsing to work.  Not sure how clear this is but your config is fine.  I am guessing you may have been running into a known issue regarding statics and arp in the 6.3 code.  Glad you got it fixed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2004 18:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-os-version-6-3-1-bug/m-p/302813#M594393</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2004-02-25T18:28:27Z</dc:date>
    </item>
  </channel>
</rss>

