<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with PIX 500 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-pix-500/m-p/1468253#M635146</link>
    <description>&lt;P&gt;I have a pix 500 firewall box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a system which is on DMZ and IP is 10.40.1.16, there is webserver running on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whenever VPN users connect to VPN they are unable to access this system. But the moment they disconnect VPN they are able to connect because it is routed with a public IP. I want VPN users to access this system without disconnecting VPN ( I mean after they connect to VPN ). VPN IP is 10.255.1.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added an access list as given below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraph"&gt;&lt;SPAN&gt;access-list bastion permit &lt;STRONG&gt;ip&lt;/STRONG&gt; 10.255.1.0 255.0.0.0 host 10.40.1.16&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-list bastion permit &lt;STRONG&gt;ip&lt;/STRONG&gt; 10.40.1.16 host 10.255.1.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when add this list " access-list bastion permit &lt;STRONG&gt;ip&lt;/STRONG&gt; 10.255.1.0 255.0.0.0 host 10.40.1.16 " I receive an error message &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;access-list nonat permit ip 10.255.1.0 255.255.0.0 10.40.1.16 255.255.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;ERROR: Global address,mask &amp;lt;10.255.1.0,255.255.0.0&amp;gt; doesn't pair&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;Type help or '?' for a list of available commands.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Can someone help me to rectify this problem?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Regards&lt;/P&gt;&lt;P class="MsoNormal"&gt;Tonio&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 17:56:42 GMT</pubDate>
    <dc:creator>toniogeorge</dc:creator>
    <dc:date>2019-03-11T17:56:42Z</dc:date>
    <item>
      <title>Problem with PIX 500</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-pix-500/m-p/1468253#M635146</link>
      <description>&lt;P&gt;I have a pix 500 firewall box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a system which is on DMZ and IP is 10.40.1.16, there is webserver running on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whenever VPN users connect to VPN they are unable to access this system. But the moment they disconnect VPN they are able to connect because it is routed with a public IP. I want VPN users to access this system without disconnecting VPN ( I mean after they connect to VPN ). VPN IP is 10.255.1.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added an access list as given below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraph"&gt;&lt;SPAN&gt;access-list bastion permit &lt;STRONG&gt;ip&lt;/STRONG&gt; 10.255.1.0 255.0.0.0 host 10.40.1.16&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-list bastion permit &lt;STRONG&gt;ip&lt;/STRONG&gt; 10.40.1.16 host 10.255.1.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when add this list " access-list bastion permit &lt;STRONG&gt;ip&lt;/STRONG&gt; 10.255.1.0 255.0.0.0 host 10.40.1.16 " I receive an error message &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;access-list nonat permit ip 10.255.1.0 255.255.0.0 10.40.1.16 255.255.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;ERROR: Global address,mask &amp;lt;10.255.1.0,255.255.0.0&amp;gt; doesn't pair&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;Type help or '?' for a list of available commands.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Can someone help me to rectify this problem?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Regards&lt;/P&gt;&lt;P class="MsoNormal"&gt;Tonio&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:56:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-pix-500/m-p/1468253#M635146</guid>
      <dc:creator>toniogeorge</dc:creator>
      <dc:date>2019-03-11T17:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with PIX 500</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-pix-500/m-p/1468254#M635147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears you are trying a wildcard mask instead of the regular mask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-list bastion permit &lt;STRONG&gt;ip&lt;/STRONG&gt; 10.255.1.0 255.255.255.0 host 10.40.1.16&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try the above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jun 2010 11:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-pix-500/m-p/1468254#M635147</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-06-09T11:22:11Z</dc:date>
    </item>
  </channel>
</rss>

