<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515: Help adding a line to the access list in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547704#M636476</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've added both to see if it would make a difference and it didn't.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Sep 2010 14:54:08 GMT</pubDate>
    <dc:creator>salixcapital</dc:creator>
    <dc:date>2010-09-16T14:54:08Z</dc:date>
    <item>
      <title>PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547690#M636462</link>
      <description>&lt;P&gt;Hi, I need to open a port on a PIX 515.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please can someone explain what I should be entering including the commands.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;For the purposes of the explanation (so I can understand it &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; ) I've given the different elements the following ips&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port = PPPPP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination IP that the machine s on my network will be contacting: XXX.XXX.XXX.XXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The workstation on my network YYY.YYY.YYY.YYY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX IP: ZZZ.ZZZ.ZZZ.ZZZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have logged onto the PIX via Hyperterminal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547690#M636462</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2019-03-11T18:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547691#M636463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmmmmmm wouldn't it be better to use ASDM or PDM if you don't know how to do it from CLI?&lt;/P&gt;&lt;P&gt;What's the software version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7.0+ versions support "line" argument when defining access-list entries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 09:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547691#M636463</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-09-16T09:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547692#M636464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm on 6.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can access the list and add the entry (i think) but how do i then save it? Does the firewall need a power cycle for it to work or will 'reload' work?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 10:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547692#M636464</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2010-09-16T10:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547693#M636465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't see why a reload would be needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've checked comm reff for 6.3&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/ab.html#wp1067755"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/ab.html#wp1067755&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it does support "line" argeument.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list NAME line X permit/deny etc etc....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 10:11:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547693#M636465</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-09-16T10:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547694#M636466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;write term brings up an long access list for in and out but show access-lists in only has two lines in it. How can this be?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 10:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547694#M636466</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2010-09-16T10:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547695#M636467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Show us the running config &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 10:31:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547695#M636467</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-09-16T10:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547696#M636468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the entries come in in the in and out access lists but the port is still closed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 10:42:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547696#M636468</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2010-09-16T10:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547697#M636469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This firewall has been inherited from an umbrella company that we no longer work with so i'm guessing a lot of the entries are redundant&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;access-list acl_in permit tcp any any eq www&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq ftp&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq ftp-data&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq https&lt;/P&gt;&lt;P&gt;access-list acl_in remark Cearbhall: CITADEL&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 504&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 3389&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq domain log&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp host Sloop any eq smtp&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any range 8194 8294&lt;/P&gt;&lt;P&gt;access-list acl_in remark Cearbhall, 14-Jan. SIP UDP Range&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any range 10000 32766&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 15443&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 16443&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 17443&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 18443&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 4901&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 5060&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 5060&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 5061&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 5004&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any range 16348 32766&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 5961&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 7311&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 7312&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 7315&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any range 7200 7205&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any range 5800 5900&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq pop3&lt;/P&gt;&lt;P&gt;access-list acl_in remark Cearbhall. 17-Jan&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq imap4&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq pcanywhere-data&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 5632&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 32761&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 7070 7071&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 554&lt;/P&gt;&lt;P&gt;access-list acl_in remark SAMBA at TCP/139&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 135 netbios-ssn&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 1225 1226&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq pptp&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 2189 2196&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 13678&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 7443&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 7443&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 27524&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 8194 8294&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq smtp&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq telnet&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 4899&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq citrix-ica&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 5800 5900&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 3230 3235&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 1720&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq h323&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 11000&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 4600&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 4600&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 4001 4002&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 2147&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any range 3230 3253&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 8080&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 1503&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 3230 3253&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq nntp&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 1863&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 27030 27039&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any range 27000 27015&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 1200&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 81&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 465&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 995&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 62515&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 10000&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 4500&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any range 5101 5102&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any range 5101 5102&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 37777&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 37777&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq aol&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq isakmp&lt;/P&gt;&lt;P&gt;access-list acl_in permit esp any any&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 38000&lt;/P&gt;&lt;P&gt;access-list acl_in remark Allow ICMP TO DMZ&lt;/P&gt;&lt;P&gt;access-list acl_in permit icmp 10.10.0.0 255.255.255.0 host 10.10.1.95&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp 10.10.0.0 255.255.255.0 host 10.10.1.95 eq telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp 10.10.0.0 255.255.255.0 host 10.10.1.95 eq ssh&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq tftp&lt;/P&gt;&lt;P&gt;access-list acl_in remark MONDAY&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any range 5060 5064&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq domain log&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq ntp&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq ssh&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 2443&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 2000&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 585&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp any any eq 998&lt;/P&gt;&lt;P&gt;access-list acl_in permit icmp any any&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 5036&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any eq 4569&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any any range 48129 65534&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list acl_in permit tcp any any eq 12328&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 83.71.190.91 eq www&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 83.71.190.91 range 3230 3235&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any host 83.71.190.91 range 3230 3247&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 83.71.190.91 eq h323&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 83.71.190.91 range 3230 3253&lt;/P&gt;&lt;P&gt;access-list acl_out remark AWFUL SECURITY. TIDY UP. 22-JAN&lt;/P&gt;&lt;P&gt;access-list acl_out permit ip any host Barge&lt;/P&gt;&lt;P&gt;access-list acl_out remark AWFUL SECURITY - Tidy up. 22-JAN&lt;/P&gt;&lt;P&gt;access-list acl_out permit icmp any host Barge&lt;/P&gt;&lt;P&gt;access-list acl_out remark TFTP Server (for SIP downloads, etc)&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any eq tftp any&lt;/P&gt;&lt;P&gt;access-list acl_out remark TFTP Server (for SIP downloads, etc) - Ceatbhall 14-J&lt;/P&gt;&lt;P&gt;an&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any any eq tftp&lt;/P&gt;&lt;P&gt;access-list acl_out remark Cisco 7960 Phone settings.&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any any range 16384 32766&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any eq ssh any&lt;/P&gt;&lt;P&gt;access-list acl_out remark Cearbhall, MONDAY&lt;/P&gt;&lt;P&gt;access-list acl_out remark Cearbhall, JAN 16 - WEBMIN&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any eq 10000 any&lt;/P&gt;&lt;P&gt;access-list acl_out remark Cearbhall, JAN 16 - WUsage&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any eq 2396 any&lt;/P&gt;&lt;P&gt;access-list acl_out remark Cearbhall, JAN 14&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any eq https any&lt;/P&gt;&lt;P&gt;access-list acl_out remark Cearbhall, JAN 14&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any eq www any&lt;/P&gt;&lt;P&gt;access-list acl_out remark Cearbhall, JAN-17&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any eq imap4 any&lt;/P&gt;&lt;P&gt;access-list acl_out remark MONDAY&lt;/P&gt;&lt;P&gt;access-list acl_out remark MONDAY&lt;/P&gt;&lt;P&gt;access-list acl_out remark MONDAY - ssh&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any eq ssh any eq ssh&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any any eq 504&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any any eq 2000&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any any eq 2443&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any any eq imap4&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any any eq 465&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any any eq 585&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any any eq 998&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any any eq https&lt;/P&gt;&lt;P&gt;access-list acl_out permit icmp any any&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any any eq domain&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any any range 10000 32766&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any any eq 5004&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any any eq 5036&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any any eq 4569&lt;/P&gt;&lt;P&gt;access-list acl_out permit icmp any host 87.198.182.67&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq telnet&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq www&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq domain&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq ssh&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq smtp&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq https&lt;/P&gt;&lt;P&gt;access-list acl_out remark Allow IMAP4 IN TO DMZ SERVER SLOOP&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq imap4&lt;/P&gt;&lt;P&gt;access-list acl_out remark Allow POP3 IN TO DMZ SERVER SLOOP&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq pop3&lt;/P&gt;&lt;P&gt;access-list acl_out remark Allow CITADEL IN TO DMZ SERVER SLOOP&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq 504&lt;/P&gt;&lt;P&gt;access-list acl_out remark Allow FTP IN TO DMZ SERVER SLOOP&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq ftp&lt;/P&gt;&lt;P&gt;access-list acl_out remark Allow TFTP IN TO DMZ SERVER SLOOP - Cearbhall 14-Jan&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any host 87.198.182.67 eq tftp&lt;/P&gt;&lt;P&gt;access-list acl_out remark Allow FTP-DATA IN TO DMZ SERVER SLOOP&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 eq ftp-data&lt;/P&gt;&lt;P&gt;access-list acl_out remark MONDAY&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 87.198.182.67 range 5060 5064&lt;/P&gt;&lt;P&gt;access-list acl_out remark MONDAY&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any host 87.198.182.67 range 16348 32766&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any host 87.198.182.67 range 5060 5064&lt;/P&gt;&lt;P&gt;access-list acl_out permit udp any any range 48129 65534&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;access-list acl_out permit tcp any any eq 12328&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 any eq telnet&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 eq www any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark Cearbhall. 18-Jan (FUNAMBOL)&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 eq 8080 any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark Cearbhall. 18-Jan (SAMBA)&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 eq 8080 any range 137 netbi&lt;/P&gt;&lt;P&gt;os-ssn&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark Cearbhall. 18-Jan (SAMBA)&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit udp host 10.10.1.95 any range netbios-ns 139&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark Cearbhall. 18-Jan (SAMBA)&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit udp host 10.10.1.95 any eq 445&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark Cearbhall. 18-Jan (SAMBA)&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 object-group Sloop any eq 4&lt;/P&gt;&lt;P&gt;45&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark Cearbhall. 24-Jan (LDAP)&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 any eq ldap&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 eq https any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark Cearbhall. 14-Jan&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 any eq imap4&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark Cearbhall. 14-Jan Part II&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 eq imap4 any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 eq domain any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 10.10.0.0 255.255.255.0 eq&lt;/P&gt;&lt;P&gt;telnet&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 10.10.0.0 255.255.255.0 eq&lt;/P&gt;&lt;P&gt;ssh log&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 10.10.1.95 eq ssh any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit icmp host 10.10.1.95 any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark Allow ALL OUT from&amp;nbsp; DMZ to SERVER SLOOP&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit ip host 10.10.1.95 any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit ip host 10.10.1.95 10.10.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark COD 22_JAN (Allow ICMP from DMZ - Inside)&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp any any eq imap4&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp any any eq 465&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp any any eq 585&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp any any eq 998&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp any any eq smtp&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit icmp any any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit udp any any eq domain&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit udp any any range 10000 32766&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp any any range 5059 5064&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit udp any any eq tftp&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit udp any any range 16384 32766&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit udp any any eq 5004&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit udp any any eq 4569&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit udp any any eq 5036&lt;/P&gt;&lt;P&gt;access-list acl-in remark Cearbhall SSH 26-JAN&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any any eq ssh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 10:44:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547697#M636469</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2010-09-16T10:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547698#M636470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only access-lists you should be worried about, are the ones applied anywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're looking on interface ACLs check the access-groups:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/ab.html#wp1025611"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/ab.html#wp1025611&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 11:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547698#M636470</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-09-16T11:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547699#M636471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX(config)# show interface&lt;/P&gt;&lt;P&gt;interface e&lt;STRONG&gt;thernet0 "outside"&lt;/STRONG&gt; is up, line protocol is up&lt;/P&gt;&lt;P&gt;&amp;nbsp; Hardware is i82559 ethernet, address is 0003.6bf7.2e54&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP address 87.198.182.66, subnet mask 255.255.255.240&lt;/P&gt;&lt;P&gt;&amp;nbsp; MTU 1500 bytes, BW 100000 Kbit full duplex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 760661 packets input, 189581999 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received 119 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 447171 packets output, 44433633 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 babbles, 0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 lost carrier, 0 no carrier&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input queue (curr/max blocks): hardware (128/128) software (0/18)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; output queue (curr/max blocks): hardware (0/34) software (0/1)&lt;/P&gt;&lt;P&gt;interface &lt;STRONG&gt;ethernet1 "inside"&lt;/STRONG&gt; is up, line protocol is up&lt;/P&gt;&lt;P&gt;&amp;nbsp; Hardware is i82559 ethernet, address is 0003.6bf7.2e55&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP address 10.10.0.7, subnet mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; MTU 1500 bytes, BW 100000 Kbit full duplex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 581199 packets input, 53428322 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received 1004 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 871046 packets output, 211157320 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 babbles, 0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 lost carrier, 0 no carrier&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input queue (curr/max blocks): hardware (128/128) software (0/69)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; output queue (curr/max blocks): hardware (1/70) software (0/1)&lt;/P&gt;&lt;P&gt;interface &lt;STRONG&gt;ethernet2 "DMZ"&lt;/STRONG&gt; is up, line protocol is down&lt;/P&gt;&lt;P&gt;&amp;nbsp; Hardware is i82559 ethernet, address is 0002.b3cd.97df&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP address 10.10.1.1, subnet mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; MTU 1500 bytes, BW 10000 Kbit half duplex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 packets input, 0 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received 0 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1323 packets output, 79380 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;acl_in&lt;/STRONG&gt; and &lt;STRONG&gt;acl_out&lt;/STRONG&gt; are the 2 access lists that i need to implement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What interface should they be added to and which commands should i enter to do so?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, i'm new to all this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 12:09:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547699#M636471</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2010-09-16T12:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547700#M636472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX1# show access-group&lt;/P&gt;&lt;P&gt;access-group acl_out in interface outside&lt;/P&gt;&lt;P&gt;access-group acl_in in interface inside&lt;/P&gt;&lt;P&gt;access-group DMZ_access_in in interface DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They seem to be implemented but the port is still closed (port 12328)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 12:16:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547700#M636472</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2010-09-16T12:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547701#M636473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the direction of the traffic? Are you trying to open the port from inside clients to the internet (server is on the internet) or are you trying to open the port for internet clients (Server is in your network)? If you are trying to do the later, then you need to have a NAT statement mapping the server to a publicly routable IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) tcp interface 12368 &lt;INSIDE server="" ip=""&gt; 12368 netmask 255.255.255.255&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would like to use a different IP than the interface IP, then&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) tcp xxx.yyy.zzz.kkk 12368 &lt;INSIDE server="" ip=""&gt; 12368 netmask 255.255.255.255&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your access-list is already allowing the traffic. So, once you have the NAT statement, it should work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 12:34:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547701#M636473</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-09-16T12:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547702#M636474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to open the port so users on my network can use a demo of some trading software which needs to access a remote server across the internet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 12:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547702#M636474</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2010-09-16T12:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547703#M636475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you users access the Internet normally via this pix ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure the port is TCP and not UDP ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 14:51:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547703#M636475</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-09-16T14:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547704#M636476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've added both to see if it would make a difference and it didn't.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 14:54:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547704#M636476</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2010-09-16T14:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547705#M636477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you seeing hits on the rule in your acl applied to the inside interface ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does the software work ? ie. it is a normal client/server app or does it do something funny like try to initiate a connection back to your clients ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you spoken to the company hosting the software to see if they can see requests coming from your public IP ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My previous question about general internet access was to make sure NAT is setup correctly. Perhaps you could post the NAT config ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 14:57:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547705#M636477</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-09-16T14:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547706#M636478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX# show NAT&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (DMZ) 1 10.10.0.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX(config)# show access-list inside_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl turbo-configured; 1 elements&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl line 1 permit ip 10.10.0.0 255.255.255.0 10&lt;/P&gt;&lt;P&gt;.10.0.0 255.255.255.0 (hitcnt=110)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is show NAT the right command?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 15:17:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547706#M636478</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2010-09-16T15:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547707#M636479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;salixcapital wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX# show NAT&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (DMZ) 1 10.10.0.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX(config)# show access-list inside_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl turbo-configured; 1 elements&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl line 1 permit ip 10.10.0.0 255.255.255.0 10&lt;/P&gt;&lt;P&gt;.10.0.0 255.255.255.0 (hitcnt=110)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is show NAT the right command?&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, as long as you have something like -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 &lt;IP address=""&gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 15:23:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547707#M636479</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-09-16T15:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547708#M636480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so does that look correct in my case?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will i just post the entire 'write term'?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 15:25:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547708#M636480</guid>
      <dc:creator>salixcapital</dc:creator>
      <dc:date>2010-09-16T15:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515: Help adding a line to the access list</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547709#M636481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks fine. Can you internal users access internet web sites ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that you can run debug on the pix to see if the packet is leaving your pix and if you are receiving anything in return eg.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug packet outside dst &lt;IP address="" of="" software="" server=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;-- this should show you packets leaving your pix when an internal client tries to connect to the remote server&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug packet outside src &lt;IP address="" of="" software="" server=""&gt;&amp;nbsp; &amp;lt;--- this should show you packets arriving at the outside interface of your pix from the remote server&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However be careful with debug. You don't want to run it during peak hours, best to test out of core hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 15:48:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-help-adding-a-line-to-the-access-list/m-p/1547709#M636481</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-09-16T15:48:02Z</dc:date>
    </item>
  </channel>
</rss>

