<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Config help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-config-help/m-p/183867#M600397</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I think the reason I did the Nat (inside) 0 line was because I thought I needed that in order to get my network-object to work right.  Is my network-object set up right in order to get PcAnywhere to work with NAT for that Internal block (10.0.0.30-80)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did try pinging from hosts on one interface to hosts on another when I tried to install this thing, and I didn't get any response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other recommendations, or does anybody see anything else that might cause me some problems?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Aug 2003 03:45:50 GMT</pubDate>
    <dc:creator>abruso</dc:creator>
    <dc:date>2003-08-26T03:45:50Z</dc:date>
    <item>
      <title>PIX Config help</title>
      <link>https://community.cisco.com/t5/network-security/pix-config-help/m-p/183865#M600386</link>
      <description>&lt;P&gt;This past weekend, I tried implementing a PIX into our existing network.  After getting everything hooked up, and my config entered into the pix, I had some issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sitting on the PIX, I could ping any host I wanted.&lt;/P&gt;&lt;P&gt;Sitting on a host in the Internal network, I could ping the Internal PIX interface, but I could not ping the Outside, or DMZ interfaces or any hosts connected to those interfaces.&lt;/P&gt;&lt;P&gt;Sitting on a host in the DMZ, I could ping the DMZ interface on the PIX, but I could not ping the other two interfaces or any hosts connected tot hose interfaces.  Sitting on a host on the outside, I could ping the outside interface of the PIX, but I could not ping the other two interfaces or any hosts connected to them.&lt;/P&gt;&lt;P&gt;Here is the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(2)&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;interface ethernet2 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 DMZ security50&lt;/P&gt;&lt;P&gt;enable password &lt;/P&gt;&lt;P&gt;hostname xxxxx&lt;/P&gt;&lt;P&gt;domain-name xxxxxx&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol ils 389&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;no fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;object-group network pcanywhere&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.30 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.31 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.32 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.33 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.34 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.35 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.36 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.37 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.38 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.39 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.40 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.41 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.42 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.43 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.44 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.45 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.46 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.47 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.48 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.49 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.50 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.51 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.52 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.53 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.54 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.55 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.56 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.57 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.58 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.59 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.60 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.61 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.62 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.63 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.64 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.65 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.66 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.67 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.68 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.69 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.70 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.71 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.72 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.73 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.74 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.75 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.76 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.77 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.78 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.79 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host 10.0.0.80 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 216.27.xxx.xxx eq www&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp host 216.27.xxx host 216.27.xxx.xxx eq smtp&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 216.27.xxx.xxx eq syslog&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 216.27.xxx.xxx eq 443&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any object-group pcanywhere eq 5631&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit udp any object-group pcanywhere eq 5632&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging monitor debugging&lt;/P&gt;&lt;P&gt;logging buffered errors&lt;/P&gt;&lt;P&gt;logging trap debugging&lt;/P&gt;&lt;P&gt;logging history errors&lt;/P&gt;&lt;P&gt;logging host dmz 192.168.0.5&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu State-Fail 1500&lt;/P&gt;&lt;P&gt;ip address outside 216.27.xxx.xxx 255.255.255.240&lt;/P&gt;&lt;P&gt;ip address inside 10.0.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address DMZ 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00&lt;/P&gt;&lt;P&gt;failover poll 3&lt;/P&gt;&lt;P&gt;pdm logging debugging 100&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (inside) 0 10.0.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (dmz,outside) 216.27.xxx.xxx 192.168.0.100 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (dmz,outside) 216.27.xxx.xxx 192.168.0.5 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 216.27.224.81 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 10.0.0.0 255.0.0.0 inside&lt;/P&gt;&lt;P&gt;no floodguard enable&lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec&lt;/P&gt;&lt;P&gt;sysopt connection permit-pptp&lt;/P&gt;&lt;P&gt;sysopt noproxyarp outside&lt;/P&gt;&lt;P&gt;sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;telnet 10.0.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 10.0.0.0 255.0.0.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;vpdn enable outside&lt;/P&gt;&lt;P&gt;vpdn enable inside&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm guessing it's a problem with the NAT translations in the PIX, but I have no idea what it is.  I am pretty new at this stuff.  Any help would be appreciated.  Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-config-help/m-p/183865#M600386</guid>
      <dc:creator>abruso</dc:creator>
      <dc:date>2020-02-21T06:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Config help</title>
      <link>https://community.cisco.com/t5/network-security/pix-config-help/m-p/183866#M600391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First thing, you won't be able to ping a PIX interface from a host on another PIX interface, so don't even bother trying that.  To test connectivity you need to ping from a host on one interface to a host on another.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, to go from a higher security int to a lower security int (inside -&amp;gt; outside, inside -&amp;gt; dmz or dmz -&amp;gt; outside), you need a nat/global pair for those two interfaces.  For example, to go from an inside host to a dmz host you need the following:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; nat (inside) 2 10.0.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;gt; global (dmz) 2 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note the "2", this pairs up the nat and the global statement, the number can be anything, but as long as you have at least one of each statement you'll be good to go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, to go from inside to outside do the following:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; nat (inside) 3 10.0.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;gt; global (outside) 3 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and to go from dmx to outside do:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; nat (dmz) 4 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;gt; global (outside) 4 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more thing, in your config you have a "nat 0" statement for the inside, "0" is a special number which means DON'T NAT this traffic.  With your config all traffic from the inside network would not have been NAT'd ("nat 0" takes precedence over "nat &lt;ANY number=""&gt;"), so your packets would have gone out the Internet sourced with a 10.x.x.x address and not be able to come back.  Get rid of this "nat 0" statement  otherwise nothing will still work.&lt;/ANY&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2003 02:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-config-help/m-p/183866#M600391</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-08-26T02:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Config help</title>
      <link>https://community.cisco.com/t5/network-security/pix-config-help/m-p/183867#M600397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I think the reason I did the Nat (inside) 0 line was because I thought I needed that in order to get my network-object to work right.  Is my network-object set up right in order to get PcAnywhere to work with NAT for that Internal block (10.0.0.30-80)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did try pinging from hosts on one interface to hosts on another when I tried to install this thing, and I didn't get any response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other recommendations, or does anybody see anything else that might cause me some problems?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2003 03:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-config-help/m-p/183867#M600397</guid>
      <dc:creator>abruso</dc:creator>
      <dc:date>2003-08-26T03:45:50Z</dc:date>
    </item>
  </channel>
</rss>

