<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fixup, on the PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57384#M728156</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I read that can not change the default port for RSH (534). If it is possible, what version software can do it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Nov 2001 22:13:01 GMT</pubDate>
    <dc:creator>ddhmhernandez</dc:creator>
    <dc:date>2001-11-15T22:13:01Z</dc:date>
    <item>
      <title>fixup, on the PIX</title>
      <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57382#M728151</link>
      <description>&lt;P&gt;What exactly does the command "fixup protocol rsh"?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:54:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57382#M728151</guid>
      <dc:creator>cmontes</dc:creator>
      <dc:date>2020-02-21T05:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: fixup, on the PIX</title>
      <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57383#M728154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;-Defines ports for rsh connections: (default = 514)&lt;/P&gt;&lt;P&gt;"fixup protocol rsh 1234"&lt;/P&gt;&lt;P&gt;-Dynamically opens port for rsh standard error connections&lt;/P&gt;&lt;P&gt;If disabled:&lt;/P&gt;&lt;P&gt;"no fixup protocol rsh"&lt;/P&gt;&lt;P&gt;-Outbound rsh will not work&lt;/P&gt;&lt;P&gt;-Inbound rsh will work if conduit (or access-list) exists&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2001 21:23:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57383#M728154</guid>
      <dc:creator>vitaliy.pindyura</dc:creator>
      <dc:date>2001-11-15T21:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: fixup, on the PIX</title>
      <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57384#M728156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I read that can not change the default port for RSH (534). If it is possible, what version software can do it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2001 22:13:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57384#M728156</guid>
      <dc:creator>ddhmhernandez</dc:creator>
      <dc:date>2001-11-15T22:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: fixup, on the PIX</title>
      <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57385#M728159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What exactly means "dynamically", all the outbound traffic is allowed and the inbound traffic is blocked or what does it means?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2001 23:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57385#M728159</guid>
      <dc:creator>ddhmhernandez</dc:creator>
      <dc:date>2001-11-15T23:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: fixup, on the PIX</title>
      <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57386#M728162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What exactly means "dynamically", all the outbound traffic is allowed and the inbound traffic is blocked or what does it means?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2001 23:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57386#M728162</guid>
      <dc:creator>ddhmhernandez</dc:creator>
      <dc:date>2001-11-15T23:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: fixup, on the PIX</title>
      <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57387#M728164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;In response to: ddhmhernandez - Service Engineer, GETRONICS  &lt;/P&gt;&lt;P&gt;&amp;gt;Nov 15, 2001, 2:13pm Pacific   (1.1) &lt;/P&gt;&lt;P&gt;&amp;gt;I read that can not change the default port for RSH (534). If it is possible, what version software can do it?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You SHOULD NOT change the port values for RSH and SIP (Session Initiation Protocol), but you CAN change it. I am using v.6.1.1 on the PIX-520 and below is an actual configuration (see the last line) &lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;PIX Version 6.1(1)&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol h323 1720&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol rsh 9999&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2001 23:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57387#M728164</guid>
      <dc:creator>vitaliy.pindyura</dc:creator>
      <dc:date>2001-11-15T23:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: fixup, on the PIX</title>
      <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57388#M728168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are two channels between Client and Server:&lt;/P&gt;&lt;P&gt;- Client-initiated command connection (TCP)&lt;/P&gt;&lt;P&gt;- Server-initiated standard error connection (TCP)&lt;/P&gt;&lt;P&gt;PIX will handle:&lt;/P&gt;&lt;P&gt;1. Inbound connections&lt;/P&gt;&lt;P&gt;- If outbound traffic is allowed, no special handling is required&lt;/P&gt;&lt;P&gt;- If outbound traffic is not allowed, open the outbound port for standard error output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Outbound connections&lt;/P&gt;&lt;P&gt;- Open inbound port for standard error output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2001 23:56:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57388#M728168</guid>
      <dc:creator>vitaliy.pindyura</dc:creator>
      <dc:date>2001-11-15T23:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: fixup, on the PIX</title>
      <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57389#M728171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the answer, but I am having some problems trying to understand your answer.&lt;/P&gt;&lt;P&gt;In another words, if the command: "fixup protocol rsh" is in the PIX configuration this means:&lt;/P&gt;&lt;P&gt;- The port is open for access from the internet?&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;- Do I need a conduit command, in order that someone from internet access the network/intranet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have some documentation where I can read about "fixup protocol RSH" in the PIX ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2001 00:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57389#M728171</guid>
      <dc:creator>ddhmhernandez</dc:creator>
      <dc:date>2001-11-16T00:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: fixup, on the PIX</title>
      <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57390#M728176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the port is open for access from the Internet has nothing to do with fixup commands. You need a access-list entry or conduit statement to allow RSH in.&lt;/P&gt;&lt;P&gt;What 'fixup protocol rsh' does is looking into the packets to determine which ports should be allowed through the firewall on a temporarily basis. &lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;A client (on the Internal network) opens a RSH session on port 514 with an external server. The client informs the server on which port it will listen for error messages (say port 2110). The PIX firewall picks up this information (via the fixup feature) and allow the server to send rsh error messages to the client by opening inbound traffic to port 2110 for the duration of the session.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2001 23:34:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57390#M728176</guid>
      <dc:creator>rrbleeker</dc:creator>
      <dc:date>2001-11-22T23:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: fixup, on the PIX</title>
      <link>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57391#M728180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;    I agree on the oint that , fixup protocol command tells the PIX to listen on that specified port for that specified protocol.if the port no. specified for ex. for FTP os changed from the default value of 21 , then the control functions dont work on the port 21 anymore .&lt;/P&gt;&lt;P&gt;   But theres a mistake on the configuration posted above by Mr. Vitaly , coz the port for fixup protocol in PIX cannot be changed for "rsh" and also "sip" ,this doesnt work at all.so&lt;/P&gt;&lt;P&gt;for rsh it shld always be "fixup protocol rsh 514 " and nothin else.&lt;/P&gt;&lt;P&gt;   Please do refer to the below link for further clarifications reagdrin this and any other doubts regardin the "fixup protocol" command, i think this helps, if theres anythin wrong in what i said , please enlighten me on the same friends !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_61/cmd_ref/df.htm#xtocid1116813" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_61/cmd_ref/df.htm#xtocid1116813&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2001 07:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-on-the-pix/m-p/57391#M728180</guid>
      <dc:creator>vipin.radhakrishnan</dc:creator>
      <dc:date>2001-11-23T07:34:29Z</dc:date>
    </item>
  </channel>
</rss>

