<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Config problems. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211464#M595152</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, sorry for not being more specific. I am setting the PIX up in a test lab, for the time being. Eventually it will be deployed to the Corp. network but we have testing to do first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Test: Set up the Firewall to allow normal connections out (http, FTP, PC-anywhere, etc...) and restrict access back in. after that I have to start blocking streaming media in, my web guys are going to try to hack it so they can get the media past most firewalls (our company lives off streaming media purchised by other companies and we have problems every now and then with their firewalls, thus the test).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After these tests, the PIX will serve as our company firewall with normal access to mail and what not (web-etc...)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I read through the manual and it seems I have everything set up right but it fails my tests (i.e. tested a block out-bound http port 80) yet the web traffic still gets through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.2.0 (inside PIX) --&amp;gt; 10.0.2.0 (corporate net) --&amp;gt; I-net.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Jan 2004 17:24:12 GMT</pubDate>
    <dc:creator>jon.hamilton</dc:creator>
    <dc:date>2004-01-26T17:24:12Z</dc:date>
    <item>
      <title>PIX Config problems.</title>
      <link>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211462#M595144</link>
      <description>&lt;P&gt;So I am configuring my PIX 506E through PDM and am having problems getting the rules to work properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I really need is an example config of how it should look, blocking in bound ports and some out bound ports. I have tried many variations and have yet to nail the config. RTFM, done it and it seems that the Manuel and the actual way it works is different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chances are that I am just missing something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help on this is much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:12:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211462#M595144</guid>
      <dc:creator>jon.hamilton</dc:creator>
      <dc:date>2020-02-21T07:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Config problems.</title>
      <link>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211463#M595149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to be specific for what you are looking for. There is alot of stuff, infact the entire configs that can be done with PDM. Basically the online guide is the only one available .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know what rules you are saying you are having problems with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Jan 2004 01:18:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211463#M595149</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-01-24T01:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Config problems.</title>
      <link>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211464#M595152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, sorry for not being more specific. I am setting the PIX up in a test lab, for the time being. Eventually it will be deployed to the Corp. network but we have testing to do first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Test: Set up the Firewall to allow normal connections out (http, FTP, PC-anywhere, etc...) and restrict access back in. after that I have to start blocking streaming media in, my web guys are going to try to hack it so they can get the media past most firewalls (our company lives off streaming media purchised by other companies and we have problems every now and then with their firewalls, thus the test).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After these tests, the PIX will serve as our company firewall with normal access to mail and what not (web-etc...)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I read through the manual and it seems I have everything set up right but it fails my tests (i.e. tested a block out-bound http port 80) yet the web traffic still gets through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.2.0 (inside PIX) --&amp;gt; 10.0.2.0 (corporate net) --&amp;gt; I-net.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2004 17:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211464#M595152</guid>
      <dc:creator>jon.hamilton</dc:creator>
      <dc:date>2004-01-26T17:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Config problems.</title>
      <link>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211465#M595156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you please post the config of the pix and specify  what is no working? Please remove the passwords and public ip addresses.&lt;/P&gt;&lt;P&gt;Please specify the protocols (tcp/udp/ports) that you need to allow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2004 19:46:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211465#M595156</guid>
      <dc:creator>tvanginneken</dc:creator>
      <dc:date>2004-01-26T19:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Config problems.</title>
      <link>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211466#M595161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;PIX Version 6.3(1)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;enable password xxxx&lt;/P&gt;&lt;P&gt;passwd xxxx&lt;/P&gt;&lt;P&gt;hostname xxxxxx&lt;/P&gt;&lt;P&gt;domain-name xxxx.com&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol ils 389&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.0.2.13 xxxxx&lt;/P&gt;&lt;P&gt;name 10.0.2.1 ExternalGateway&lt;/P&gt;&lt;P&gt;object-group service allftp tcp&lt;/P&gt;&lt;P&gt;  description this covers ftp and ftp-data ports.&lt;/P&gt;&lt;P&gt;  port-object eq ftp&lt;/P&gt;&lt;P&gt;  port-object eq ftp-data&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark ICMP Allow.&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in deny ip any any &lt;/P&gt;&lt;P&gt;access-list inside_access_in deny tcp 192.168.2.0 255.255.255.0 eq www any eq www &lt;/P&gt;&lt;P&gt;access-list inside_access_in permit ip any any &lt;/P&gt;&lt;P&gt;access-list inside_access_in remark AOL IM Allow&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside 10.0.2.42 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 192.168.2.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm location 10.0.2.42 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm location 10.0.2.113 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 10.0.2.105 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 10.0.2.5 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location xxxxxxxxxx255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location ExternalGateway 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 192.168.2.34 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm logging informational 100&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;global (inside) 99 192.168.2.2-192.168.2.254 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;global (inside) 1 10.0.2.42&lt;/P&gt;&lt;P&gt;nat (inside) 0 192.168.2.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 ExternalGateway 1&lt;/P&gt;&lt;P&gt;timeout xlate 0:05:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 10.0.2.5 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;http 192.168.2.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;tftp-server outside 10.0.2.5 /tftp/ppgc-nh&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;[OK]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay, so this is weird. I looked through this config and I have rules there that are long gone...PDM doesn't show the AOL IM rule anymore...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See attached screen shot of PDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that I am simply trying to test how rules are set up so I can make my final config. I have tried several different variations of this but my interpretations of the manual say it is supposed to look like this:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2004 20:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211466#M595161</guid>
      <dc:creator>jon.hamilton</dc:creator>
      <dc:date>2004-01-26T20:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Config problems.</title>
      <link>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211467#M595164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Attached screen.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2004 20:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211467#M595164</guid>
      <dc:creator>jon.hamilton</dc:creator>
      <dc:date>2004-01-26T20:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Config problems.</title>
      <link>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211468#M595167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if something is in the config that is no longer visible in the PDM then I would recommend to reset the config. If you make changes to the configuration I would strongly recommend that you use only the PDM or only the Command Line Interface. Do not mix the PDM and the CLI. Some things you enter using the CLI may not be interpreted correctly by the PDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To reset the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;write erase&lt;/P&gt;&lt;P&gt;reload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please connect a console cable after doing this. The pix will start the configuration wizard after the commands above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2004 08:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-config-problems/m-p/211468#M595167</guid>
      <dc:creator>tvanginneken</dc:creator>
      <dc:date>2004-01-27T08:00:09Z</dc:date>
    </item>
  </channel>
</rss>

