<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 515E Outbound Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-outbound-configuration/m-p/269417#M620461</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;cut-in-paste below in your pix then it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list permit_out_in permit icmp host 212.100.211.2 host 212.100.211.50&lt;/P&gt;&lt;P&gt;access-group permit_out_in in interface outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;static (i,o) 212.100.211.1 192.168.10.1&lt;/P&gt;&lt;P&gt;static (i,o) 212.100.211.50 192.168.10.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route out 0 0 212.100.211.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;glo (out) 1 212.100.211.40-212.100.211.60&lt;/P&gt;&lt;P&gt;glo (out) 1 212.100.211.35 interface outside&lt;/P&gt;&lt;P&gt;nat (in) 1 0 0&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging con 7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;---------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you hosts PC have their gateways set correctly. PC1 should have a gateway of the outside interface of the pix. PC2 should have a gateway of the inside PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the PIX do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# ping out 212.100.211.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should be getting a reply. Then:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# ping in 192.168.10.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should be getting a reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping the inside interface of the pix from PC2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should be getting a reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now goto PC1 on the outside interface and in dos ping 212.100.211.50&lt;/P&gt;&lt;P&gt;you should get a reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is one way of doing it. You may need to use another way for your final config depending on how many global addrs you have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If for some reason you can not ping use debug icmp trace to see where the packet is going.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# debug icmp trace&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 29 Nov 2003 23:04:35 GMT</pubDate>
    <dc:creator>rgrcommo</dc:creator>
    <dc:date>2003-11-29T23:04:35Z</dc:date>
    <item>
      <title>Pix 515E Outbound Configuration</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-outbound-configuration/m-p/269415#M620445</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to setup a PIX 515E in the lab for learning .I've configured ether0 with IP address 212.100.211.1/24 and ether1 with 192.168.10.1 /24 . Ether0 Interface of Pix is connected with a PC having IP address of 212.100.211.2 /24 using cross over cable and Ether1 Interface is connected with another PC , having IP address 192.168.10.2 /24 using Cross cable. I'm trying to initiate a outbound connection from 192.168.10.2 to the PC of 212.100.211.2 ,but it does not work. I've created NAT &amp;amp; Global , no use. From this PC , I can't able to ping "outside "Interface address of PIX .From PIX , I can able to ping both the PC's connected to outside &amp;amp; Inside Interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Raju &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-outbound-configuration/m-p/269415#M620445</guid>
      <dc:creator>raju</dc:creator>
      <dc:date>2020-02-21T07:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E Outbound Configuration</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-outbound-configuration/m-p/269416#M620456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raju,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use ping for test, you have to setup an accesslist on the outside interface which permits the returning ICMP-packets. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember there is no need to setup an access-list for responsepackets on outbound tcp and udp sessions. Reason for this difference is that PIX´s ASA (the statefull inspection mechanism) does not handle ICMP, but does handle other traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, when you setup your PIX like you described, ICMP won´t work, but other traffic will. Try to telnet or http to the outside and you will see that it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Nov 2003 21:19:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-outbound-configuration/m-p/269416#M620456</guid>
      <dc:creator>l.mourits</dc:creator>
      <dc:date>2003-11-29T21:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E Outbound Configuration</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-outbound-configuration/m-p/269417#M620461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;cut-in-paste below in your pix then it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list permit_out_in permit icmp host 212.100.211.2 host 212.100.211.50&lt;/P&gt;&lt;P&gt;access-group permit_out_in in interface outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;static (i,o) 212.100.211.1 192.168.10.1&lt;/P&gt;&lt;P&gt;static (i,o) 212.100.211.50 192.168.10.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route out 0 0 212.100.211.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;glo (out) 1 212.100.211.40-212.100.211.60&lt;/P&gt;&lt;P&gt;glo (out) 1 212.100.211.35 interface outside&lt;/P&gt;&lt;P&gt;nat (in) 1 0 0&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging con 7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;---------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you hosts PC have their gateways set correctly. PC1 should have a gateway of the outside interface of the pix. PC2 should have a gateway of the inside PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the PIX do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# ping out 212.100.211.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should be getting a reply. Then:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# ping in 192.168.10.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should be getting a reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping the inside interface of the pix from PC2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should be getting a reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now goto PC1 on the outside interface and in dos ping 212.100.211.50&lt;/P&gt;&lt;P&gt;you should get a reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is one way of doing it. You may need to use another way for your final config depending on how many global addrs you have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If for some reason you can not ping use debug icmp trace to see where the packet is going.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# debug icmp trace&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Nov 2003 23:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-outbound-configuration/m-p/269417#M620461</guid>
      <dc:creator>rgrcommo</dc:creator>
      <dc:date>2003-11-29T23:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E Outbound Configuration</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-outbound-configuration/m-p/269418#M620519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jeff . It works .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Dec 2003 05:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-outbound-configuration/m-p/269418#M620519</guid>
      <dc:creator>raju</dc:creator>
      <dc:date>2003-12-01T05:17:55Z</dc:date>
    </item>
  </channel>
</rss>

