<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: pix 515 problem urgently in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175610#M604367</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need the following static &amp;amp; nat commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 200.200.200.1 200.200.200.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) 200.200.200.3 200.200.200.3 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) 200.200.200.6 200.200.200.6 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) 200.200.200.8 200.200.200.8 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And for DMZ to go out:&lt;/P&gt;&lt;P&gt;nat (dmz) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Jun 2003 00:34:46 GMT</pubDate>
    <dc:creator>bdube</dc:creator>
    <dc:date>2003-06-19T00:34:46Z</dc:date>
    <item>
      <title>pix 515 problem urgently</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175609#M604365</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I have a pix 515 with 3 interfaces, the outside interface and the DMZ interface are different subnets of one main net, which means that I have a legal net ( 200.200.200.0/26, the outside interface and the DMZ interface are 200.200.200.0/27 and 200.200.200.32/27, all the www and mail servers are located in the DMZ.  One Router is outside of the PIX.  &lt;/P&gt;&lt;P&gt;I have add the routes on the router to the DMZ net.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is from the inside  I can reach anywhere which I certainly use the nat, but from the DMZ I can not reach anywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the configuration is below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.1(1)&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 dmz security10&lt;/P&gt;&lt;P&gt;enable password xxxx encrypted&lt;/P&gt;&lt;P&gt;passwd xxxxx encrypted&lt;/P&gt;&lt;P&gt;hostname pixfirewall&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol h323 1720&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 200.200.200.1 eq domain &lt;/P&gt;&lt;P&gt;access-list 101 permit udp any host 200.200.200.1 eq domain &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 200.200.200.6 eq www &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 200.200.200.8 eq ftp &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 200.200.200.3 eq smtp &lt;/P&gt;&lt;P&gt;access-list 101 permit ip any any &lt;/P&gt;&lt;P&gt;access-list 102 permit ip any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;interface ethernet2 auto&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu dmz 1500&lt;/P&gt;&lt;P&gt;ip address outside xxxx.xxx.xxx.59 255.255.255.224&lt;/P&gt;&lt;P&gt;ip address inside xxx.xxx.xx.230 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address dmz 200.200.200.30 255.255.255.224&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 60&lt;/P&gt;&lt;P&gt;global (outside) 1 200.200.200.61&lt;/P&gt;&lt;P&gt;global (dmz) 1 200.200.200.15&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;access-group 102 in interface dmz&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 200.200.200.62 1&lt;/P&gt;&lt;P&gt;route inside 192.168.10.0 255.255.255.0 192.168.30.1 1&lt;/P&gt;&lt;P&gt;route inside 192.168.20.0 255.255.255.0 192.168.30.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;no sysopt route dnat&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxxxxxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;[OK]&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:48:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175609#M604365</guid>
      <dc:creator>cychenyan</dc:creator>
      <dc:date>2020-02-21T06:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: pix 515 problem urgently</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175610#M604367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need the following static &amp;amp; nat commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 200.200.200.1 200.200.200.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) 200.200.200.3 200.200.200.3 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) 200.200.200.6 200.200.200.6 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) 200.200.200.8 200.200.200.8 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And for DMZ to go out:&lt;/P&gt;&lt;P&gt;nat (dmz) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2003 00:34:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175610#M604367</guid>
      <dc:creator>bdube</dc:creator>
      <dc:date>2003-06-19T00:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: pix 515 problem urgently</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175611#M604368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with this solution but I don't understand access-list 101 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 200.200.200.1 eq domain &lt;/P&gt;&lt;P&gt;access-list 101 permit udp any host 200.200.200.1 eq domain &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 200.200.200.6 eq www &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 200.200.200.8 eq ftp &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 200.200.200.3 eq smtp &lt;/P&gt;&lt;P&gt;access-list 101 permit ip any any      &amp;lt;-------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the last statement should be: deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Aad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jul 2003 13:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175611#M604368</guid>
      <dc:creator>aboelhouwers</dc:creator>
      <dc:date>2003-07-01T13:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: pix 515 problem urgently</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175612#M604370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;THis is an implicit rule that happens automatically. You only need it if you want to log the deny alls, otherwise it won't get logged&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2003 00:38:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175612#M604370</guid>
      <dc:creator>adallica</dc:creator>
      <dc:date>2003-08-08T00:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: pix 515 problem urgently</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175613#M604373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Aad (good to see you here Aad *grin*)&lt;/P&gt;&lt;P&gt;The permit ip any any will drill a serious securityhole in your PIX. Your PIX is open to any traffic with this command (not implicit command like the other guy stated, cause the implicit rule depending on securitylevels is never seen in config)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not want the servers on the dmz to be reachable from the outside, the nat (dmz) 1 0.0.0.0 0.0.0.0 will do&lt;/P&gt;&lt;P&gt;The static commands provides you with the ability to let the PIX proxy-ARP on the outside interface for these adresses (no further config needed)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;K&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2003 06:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-problem-urgently/m-p/175613#M604373</guid>
      <dc:creator>l.mourits</dc:creator>
      <dc:date>2003-08-12T06:07:35Z</dc:date>
    </item>
  </channel>
</rss>

