<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Access Rule (PIX 515E) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-rule-pix-515e/m-p/1340691#M771318</link>
    <description>&lt;P&gt;I am trying to create an access rule in th e DMZ on a PIX 515E to one server in the DMZ (192.168.30.10) from two different IPs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;74.125.45.83&lt;/P&gt;&lt;P&gt;74.125.45.17&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From these two IPs I want to permit https &amp;amp; ping traffic only. This is where I'm running into a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[code]&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit icmp host 192.168.30.10 any&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit tcp host 192.168.30.10 any eq www&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit tcp host 192.168.30.10 any object-group DM_INLINE_TCP_1&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit tcp host 192.168.30.10 host 192.168.2.19 object-group SQL1433&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit tcp object-group DM_INLINE_NETWORK_2 host 64.4.33.7 eq https&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit ip any any inactive&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit object-group DM_INLINE_SERVICE_1 host 192.168.30.10 host 192.168.2.19&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit icmp any host 64.4.33.7&lt;/P&gt;&lt;P&gt;[/code]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the traffic is not coming through, what do I need to do?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:35:04 GMT</pubDate>
    <dc:creator>epohxavrio</dc:creator>
    <dc:date>2019-03-11T16:35:04Z</dc:date>
    <item>
      <title>Access Rule (PIX 515E)</title>
      <link>https://community.cisco.com/t5/network-security/access-rule-pix-515e/m-p/1340691#M771318</link>
      <description>&lt;P&gt;I am trying to create an access rule in th e DMZ on a PIX 515E to one server in the DMZ (192.168.30.10) from two different IPs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;74.125.45.83&lt;/P&gt;&lt;P&gt;74.125.45.17&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From these two IPs I want to permit https &amp;amp; ping traffic only. This is where I'm running into a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[code]&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit icmp host 192.168.30.10 any&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit tcp host 192.168.30.10 any eq www&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit tcp host 192.168.30.10 any object-group DM_INLINE_TCP_1&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit tcp host 192.168.30.10 host 192.168.2.19 object-group SQL1433&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit tcp object-group DM_INLINE_NETWORK_2 host 64.4.33.7 eq https&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit ip any any inactive&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit object-group DM_INLINE_SERVICE_1 host 192.168.30.10 host 192.168.2.19&lt;/P&gt;&lt;P&gt;access-list tsb-dmz extended permit icmp any host 64.4.33.7&lt;/P&gt;&lt;P&gt;[/code]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the traffic is not coming through, what do I need to do?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-rule-pix-515e/m-p/1340691#M771318</guid>
      <dc:creator>epohxavrio</dc:creator>
      <dc:date>2019-03-11T16:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Access Rule (PIX 515E)</title>
      <link>https://community.cisco.com/t5/network-security/access-rule-pix-515e/m-p/1340692#M771363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are the global ip addresses for the server?&lt;/P&gt;&lt;P&gt;Are the users going to be coming from the outside?&lt;/P&gt;&lt;P&gt;The you need to manipulate the outside ACL anbd maybe change the translation isd the sevrer is not translated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need something like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l outside-acl permit tcp h 74.125.45.83 h &lt;SERVER global="" ip=""&gt; eq 443&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;access-l outside-acl permit tcp h 74.125.45.17 h &lt;SERVER global="" ip=""&gt; eq 443&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;access-l outside-acl permit icmp h 74.125.45.83 h &lt;SERVER global="" ip=""&gt; &lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;access-l outside-acl permit icmp h 74.125.45.17 h &lt;SERVER global="" ip=""&gt;&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) &lt;SERVER global="" ip=""&gt; 192.168.30.10 &lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Oct 2009 17:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-rule-pix-515e/m-p/1340692#M771363</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-10-31T17:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Access Rule (PIX 515E)</title>
      <link>https://community.cisco.com/t5/network-security/access-rule-pix-515e/m-p/1340693#M771399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll try this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Oct 2009 20:07:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-rule-pix-515e/m-p/1340693#M771399</guid>
      <dc:creator>epohxavrio</dc:creator>
      <dc:date>2009-10-31T20:07:38Z</dc:date>
    </item>
  </channel>
</rss>

