<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX OWA Help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321767#M807076</link>
    <description>&lt;P&gt;I am a newby here so please go easy on me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to set up my PIX to allow OWA access so basically all I need is port 443 open to a particular server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have included the PIX config below and was wondering if someone could help point me in the right direction? I though that a line that read something like: access-list inside permit ip host SERVER13-13Exchange any&lt;/P&gt;&lt;P&gt;would have done the trick but obviously I am mistaken, can anyone help? I have just taken over this pix so if you guys spot anything blindingly obvious wrong with my config a heads up would be appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of firewall command: "sh run"&lt;BR /&gt; &lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;PIX Version 6.3(5)&lt;BR /&gt;interface ethernet0 auto&lt;BR /&gt;interface ethernet1 auto&lt;BR /&gt;interface ethernet2 auto&lt;BR /&gt;nameif ethernet0 outside security0&lt;BR /&gt;nameif ethernet1 inside security100&lt;BR /&gt;nameif ethernet2 dmz security50&lt;BR /&gt;fixup protocol dns maximum-length 512&lt;BR /&gt;fixup protocol ftp 21&lt;BR /&gt;fixup protocol h323 h225 1720&lt;BR /&gt;fixup protocol h323 ras 1718-1719&lt;BR /&gt;fixup protocol http 80&lt;BR /&gt;fixup protocol rsh 514&lt;BR /&gt;fixup protocol rtsp 554&lt;BR /&gt;fixup protocol sip 5060&lt;BR /&gt;fixup protocol sip udp 5060&lt;BR /&gt;fixup protocol skinny 2000&lt;BR /&gt;fixup protocol smtp 25&lt;BR /&gt;fixup protocol sqlnet 1521&lt;BR /&gt;fixup protocol tftp 69&lt;BR /&gt;names&lt;BR /&gt;name xx.xxx.xxx.xxx Mail-Outside&lt;BR /&gt;name xx.x.x.x OWA&lt;BR /&gt;name xx.xxx.xx.xx CNS-Management1&lt;BR /&gt;name xxx.xxx.xxx.xx CNS-Management2&lt;BR /&gt;name xx.xxx.xxx.xx Mat_Home&lt;BR /&gt;name xxx.xx.xx.xxx Spider-net1&lt;BR /&gt;name xxx.xx.xx.xxx Spider-net2&lt;BR /&gt;name xxx.xxx.xxx.xx Enterprise&lt;BR /&gt;name 192.168.0.108 SamCorbynPC7&lt;BR /&gt;name 192.168.0.103 JoPC4FTP&lt;BR /&gt;name 192.168.0.111 PC5SamBaldwin&lt;BR /&gt;name 10.0.0.3 TRIGOLDTESTPC&lt;BR /&gt;name 192.168.0.102 JohnyPC&lt;BR /&gt;name 192.168.0.150 KeithBaldwinLaptop&lt;BR /&gt;name 192.168.0.151 KeithBaldwinWirelessCard&lt;BR /&gt;name 192.168.0.122 TishPC&lt;BR /&gt;name 192.168.0.120 PC6HelenPatersonPC&lt;BR /&gt;name 192.168.0.7 SimonHinsleyPC31&lt;BR /&gt;name 192.168.0.117 MartinMiles&lt;BR /&gt;name 10.0.0.4 TrainingRouter&lt;BR /&gt;name 192.168.0.133 PC26-Nicki-FTP-Access&lt;BR /&gt;name 192.168.0.3 Server02-File-Virus&lt;BR /&gt;name 192.168.0.2 Server01-Mail-Inside&lt;BR /&gt;name 192.168.0.4 Server03-Safeword&lt;BR /&gt;name 192.168.0.115 KirstyHartleyPC32&lt;BR /&gt;name 10.0.0.1 TelephoneSupport&lt;BR /&gt;name 192.168.0.35 TelephonePABX&lt;BR /&gt;name 192.168.0.154 LAPTOP31&lt;BR /&gt;name xxx.xx.232.0 BlackspiderNew2&lt;BR /&gt;name xx.xxx.32.0 BlackspiderNew-4&lt;BR /&gt;name xxx.xxx.216.0 BlackspiderNew-3&lt;BR /&gt;name xxx.50.xx.0 BlackspiderNew-1&lt;BR /&gt;name 192.168.0.136 DEBBIELAPTOP&lt;BR /&gt;name 192.168.0.168 Laptop34Kateb&lt;BR /&gt;name 192.168.0.8 Server06-Exchange&lt;BR /&gt;name 192.168.0.34 ProxyServer&lt;BR /&gt;name 192.168.0.33 ProxyServer2&lt;BR /&gt;name 192.168.0.19 KirstyHartleyPC32-2&lt;BR /&gt;name xx.109.xxx.166 Webmail&lt;BR /&gt;name 192.168.0.13 SERVER13-13Exchange&lt;BR /&gt;name 192.168.0.12 SERVER13-12Exchange&lt;BR /&gt;name 192.168.0.18 PC38-Kay-Oblj&lt;BR /&gt;object-group service ExchangeDMZTCP tcp &lt;BR /&gt;&amp;nbsp; description TCP ports used by Exchange Front to Back End&lt;BR /&gt;&amp;nbsp; port-object eq ldap &lt;BR /&gt;&amp;nbsp; port-object eq 691 &lt;BR /&gt;&amp;nbsp; port-object eq www &lt;BR /&gt;&amp;nbsp; port-object eq 88 &lt;BR /&gt;&amp;nbsp; port-object eq 3268 &lt;BR /&gt;&amp;nbsp; port-object eq domain &lt;BR /&gt;&amp;nbsp; port-object eq 135 &lt;BR /&gt;&amp;nbsp; port-object eq 5001 &lt;BR /&gt;object-group service ExchangeDMZUDP udp &lt;BR /&gt;&amp;nbsp; description UDP ports used by Exchange Front to Back End&lt;BR /&gt;&amp;nbsp; port-object eq 389 &lt;BR /&gt;&amp;nbsp; port-object eq 88 &lt;BR /&gt;&amp;nbsp; port-object eq domain &lt;BR /&gt;&amp;nbsp; port-object eq 691 &lt;BR /&gt;&amp;nbsp; port-object eq 3268 &lt;BR /&gt;&amp;nbsp; port-object eq 2833 &lt;BR /&gt;object-group service AddMail2OWA tcp &lt;BR /&gt;&amp;nbsp; port-object eq 137 &lt;BR /&gt;&amp;nbsp; port-object eq 135 &lt;BR /&gt;&amp;nbsp; port-object eq 445 &lt;BR /&gt;object-group service AddOWAtoMail udp &lt;BR /&gt;&amp;nbsp; port-object eq netbios-ns &lt;BR /&gt;object-group service AddOWAtoMailTCP tcp &lt;BR /&gt;&amp;nbsp; port-object eq 445 &lt;BR /&gt;&amp;nbsp; port-object eq netbios-ssn &lt;BR /&gt;&amp;nbsp; port-object eq https &lt;BR /&gt;object-group service TerminalService tcp &lt;BR /&gt;&amp;nbsp; description Terminal Services for Access Sorce Server&lt;BR /&gt;&amp;nbsp; port-object eq 3389 &lt;BR /&gt;&amp;nbsp; port-object eq ssh &lt;BR /&gt;object-group service CiscoVPN udp &lt;BR /&gt;&amp;nbsp; description Cisco Outbound UDP Ports 10000 4500 500&lt;BR /&gt;&amp;nbsp; port-object range isakmp isakmp &lt;BR /&gt;&amp;nbsp; port-object range 10000 10000 &lt;BR /&gt;&amp;nbsp; port-object range 4500 4500 &lt;BR /&gt;object-group network FTPAccess &lt;BR /&gt;&amp;nbsp; network-object xxPC4FTP 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxxPC7 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxPC31 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC5xxxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxPC 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC6xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC26 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object LAPTOP31 255.255.255.255 &lt;BR /&gt;object-group network ITExtendedAccess &lt;BR /&gt;&amp;nbsp; description Extended Access For IT PCs&lt;BR /&gt;&amp;nbsp; network-object xxxxxxxxPC31 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxPC32 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC38xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxPC32-2 255.255.255.255 &lt;BR /&gt;object-group service PhoneSystem tcp &lt;BR /&gt;&amp;nbsp; description Port 5000 For our Phones&lt;BR /&gt;&amp;nbsp; port-object range 5000 5000 &lt;BR /&gt;object-group service Remotebackup tcp &lt;BR /&gt;&amp;nbsp; port-object range 4401 4408 &lt;BR /&gt;object-group service TishWEBAccess tcp &lt;BR /&gt;&amp;nbsp; description Access For Tish For Web Admin&lt;BR /&gt;&amp;nbsp; port-object range 2222 2222 &lt;BR /&gt;&amp;nbsp; port-object range 50000 60000 &lt;BR /&gt;object-group service Https tcp &lt;BR /&gt;&amp;nbsp; description SERVER04 Access for All&lt;BR /&gt;&amp;nbsp; port-object eq https &lt;BR /&gt;&amp;nbsp; port-object eq 57483 &lt;BR /&gt;object-group service RemoteBackup udp &lt;BR /&gt;&amp;nbsp; port-object range 4401 4408 &lt;BR /&gt;object-group network ExchangeServers &lt;BR /&gt;&amp;nbsp; network-object Server01-Mail-Inside 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object Server06-Exchange 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object SERVER13-12Exchange 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object SERVER13-13Exchange 255.255.255.255 &lt;BR /&gt;object-group network OWAServers &lt;BR /&gt;&amp;nbsp; description Group to Allow OWA Services&lt;BR /&gt;&amp;nbsp; network-object SERVER13-13Exchange 255.255.255.255 &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (Live)&lt;BR /&gt;access-list outside permit tcp host Spider-net1 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (Live)&lt;BR /&gt;access-list outside permit tcp host Spider-net2 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew-1 255.255.248.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew2 255.255.248.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew-3 255.255.248.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew-4 255.255.224.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside deny ip host Enterprise host Mail-Outside &lt;BR /&gt;access-list outside remark Simon Web Publishing test&lt;BR /&gt;access-list outside permit tcp any eq www host Webmail eq www &lt;BR /&gt;access-list outside remark Allow OWA Access&lt;BR /&gt;access-list outside permit tcp any host xx.109.xxx.164 eq https &lt;BR /&gt;access-list outside remark Alow Terminal Services Access&lt;BR /&gt;access-list outside permit tcp any host xx.109.xxx.165 &lt;BR /&gt;access-list outside permit tcp any eq https host xx.109.xxx.170 eq https &lt;BR /&gt;access-list inside remark Allow DNS&lt;BR /&gt;access-list inside permit udp host Server03-Safeword any eq domain &lt;BR /&gt;access-list inside remark Additonal ports required for OWA Access&lt;BR /&gt;access-list inside permit tcp host Server03-Safeword any object-group AddMail2OWA &lt;BR /&gt;access-list inside remark Blackberry SRP Communication&lt;BR /&gt;access-list inside permit tcp host Server03-Safeword any eq 3101 &lt;BR /&gt;access-list inside permit udp host Server01-Mail-Inside any eq domain &lt;BR /&gt;access-list inside remark Allow FTP for Anti-Virus&lt;BR /&gt;access-list inside permit tcp host Server02-File-Virus any eq ftp &lt;BR /&gt;access-list inside remark Allow HTTP&lt;BR /&gt;access-list inside permit tcp any any eq www &lt;BR /&gt;access-list inside remark Allow HTTPS&lt;BR /&gt;access-list inside permit tcp any any eq https &lt;BR /&gt;access-list inside remark changed for Mortgage Stream&lt;BR /&gt;access-list inside permit tcp object-group ITExtendedAccess any object-group TishWEBAccess &lt;BR /&gt;access-list inside remark Mail to Spidernet(Existing)&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside host Spider-net1 eq smtp &lt;BR /&gt;access-list inside remark Mail to Spidernet (Existing)&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside host Spider-net2 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew1&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew-1 255.255.248.0 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew2&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew2 255.255.248.0 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew3&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew-3 255.255.248.0 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew4&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew-4 255.255.224.0 eq smtp &lt;BR /&gt;access-list inside remark Ftp Access For All Recruitment&lt;BR /&gt;access-list inside permit tcp any any eq ftp &lt;BR /&gt;access-list inside remark Ftp Access For All Recruitment&lt;BR /&gt;access-list inside permit tcp object-group FTPAccess any eq ftp &lt;BR /&gt;access-list inside remark Terminal Services Access For Simon Hinsley PC For sorce Test Server&lt;BR /&gt;access-list inside permit tcp object-group ITExtendedAccess any object-group TerminalService &lt;BR /&gt;access-list inside permit udp object-group ITExtendedAccess object-group CiscoVPN any object-group CiscoVPN &lt;BR /&gt;access-list inside remark Keith Laptop Pop 3 Access&lt;BR /&gt;access-list inside permit tcp host KeithWirelessCard any eq pop3 &lt;BR /&gt;access-list inside remark Keith Wireless Card Access&lt;BR /&gt;access-list inside permit tcp host KeithWirelessCard any eq smtp &lt;BR /&gt;access-list inside permit icmp object-group ITExtendedAccess any &lt;BR /&gt;access-list inside remark Allow DNS For SERVER02&lt;BR /&gt;access-list inside permit udp host Server02-File-Virus any eq domain &lt;BR /&gt;access-list inside permit ip host Server06-Exchange any &lt;BR /&gt;access-list inside permit ip host SERVER13-12Exchange any &lt;BR /&gt;access-list inside permit ip host SERVER13-13Exchange any &lt;BR /&gt;access-list Admin_splitTunnelAcl permit ip 192.168.0.0 255.255.255.0 any &lt;BR /&gt;access-list Admin_splitTunnelAcl permit ip 10.0.0.0 255.255.255.0 any &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip 192.168.0.0 255.255.255.0 xx.16.0.0 255.255.255.0 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip host Server02-File-Virus xxx.16.0.0 255.255.255.0 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip host Server01-Mail-Inside xxx.16.0.0 255.255.255.0 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip 192.168.0.0 255.255.255.0 xxx.16.0.248 255.255.255.248 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip any 172.16.0.248 255.255.255.248 &lt;BR /&gt;access-list dmz_outbound_nat0_acl permit ip 10.0.0.0 255.255.255.0 xxx.16.0.0 255.255.255.0 &lt;BR /&gt;access-list dmz_outbound_nat0_acl permit ip 10.0.0.0 255.255.255.0 xxx.16.0.248 255.255.255.248 &lt;BR /&gt;access-list xxxxxx_splitTunnelAcl permit ip host Server02-File-Virus any &lt;BR /&gt;access-list xxxxxx_splitTunnelAcl permit ip host Server01-Mail-Inside any &lt;BR /&gt;access-list xxxxxx_splitTunnelAcl permit ip host Server03-Safeword any &lt;BR /&gt;access-list dmz_access_in permit tcp host OWA host Server01-Mail-Inside object-group ExchangeDMZTCP &lt;BR /&gt;access-list dmz_access_in permit tcp host OWA host Server03-Safeword object-group ExchangeDMZTCP &lt;BR /&gt;access-list dmz_access_in remark Unmentioned ports&lt;BR /&gt;access-list dmz_access_in permit icmp host OWA host Server03-Safeword &lt;BR /&gt;access-list dmz_access_in remark Unmentioned ports&lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server03-Safeword object-group AddOWAtoMail &lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server01-Mail-Inside object-group ExchangeDMZUDP &lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server03-Safeword object-group ExchangeDMZUDP &lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server06-Exchange object-group ExchangeDMZUDP &lt;BR /&gt;access-list dmz_access_in remark Allow OWA server to get windows updates&lt;BR /&gt;access-list dmz_access_in permit tcp host OWA any eq www &lt;BR /&gt;access-list dmz_access_in remark &lt;BR /&gt;access-list dmz_access_in permit tcp host OWA any eq https &lt;BR /&gt;access-list dmz_access_in permit udp host OWA any eq domain &lt;BR /&gt;access-list dmz_access_in remark Bug Tracker https Access for the office&lt;BR /&gt;access-list dmz_access_in permit tcp host OWA any object-group AddOWAtoMailTCP &lt;BR /&gt;access-list dmz_access_in deny tcp host TRIGOLDTESTPC any &lt;BR /&gt;access-list dmz_access_in deny udp host TRIGOLDTESTPC any &lt;BR /&gt;access-list dmz_access_in deny icmp host TRIGOLDTESTPC any &lt;BR /&gt;access-list dmz_access_in deny ip host TRIGOLDTESTPC any &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging on&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging host inside Server03-Safeword&lt;BR /&gt;no logging message 710005&lt;BR /&gt;icmp deny any outside&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu dmz 1500&lt;BR /&gt;ip address outside xx.109.xxx.162 255.255.255.240&lt;BR /&gt;ip address inside 192.168.0.1 255.255.255.0&lt;BR /&gt;ip address dmz TelephoneSupport 255.255.255.0&lt;BR /&gt;ip audit info action alarm&lt;BR /&gt;ip audit attack action alarm&lt;BR /&gt;ip local pool Admin-Pool xxx.16.0.250-xxx.16.0.254&lt;BR /&gt;ip local pool UsersPool xxx.16.0.1-xxx.16.0.249&lt;BR /&gt;pdm location Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;pdm location PC31 255.255.255.255 inside&lt;BR /&gt;pdm location OWA 255.255.255.255 inside&lt;BR /&gt;pdm location Server01-Mail-Inside 255.255.255.255 inside&lt;BR /&gt;pdm location Server02-File-Virus 255.255.255.255 inside&lt;BR /&gt;pdm location OWA 255.255.255.255 dmz&lt;BR /&gt;pdm location 172.16.0.0 255.255.255.0 outside&lt;BR /&gt;pdm location CNS-Management1 255.255.255.240 outside&lt;BR /&gt;pdm location CNS-Management2 255.255.255.240 outside&lt;BR /&gt;pdm location xx.109.xxx.16 255.255.255.240 outside&lt;BR /&gt;pdm location xxx.16.0.1 255.255.255.255 outside&lt;BR /&gt;pdm location 192.168.0.132 255.255.255.255 inside&lt;BR /&gt;pdm location PC26xxxxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location Mat_Home 255.255.255.255 outside&lt;BR /&gt;pdm location Spider-net1 255.255.255.255 outside&lt;BR /&gt;pdm location Spider-net2 255.255.255.255 outside&lt;BR /&gt;pdm location Enterprise 255.255.255.255 outside&lt;BR /&gt;pdm location xxx.205.117.82 255.255.255.255 outside&lt;BR /&gt;pdm location xxx.158.73.44 255.255.255.255 outside&lt;BR /&gt;pdm location xxxxxxPC7 255.255.255.255 inside&lt;BR /&gt;pdm location xxPC4FTP 255.255.255.255 inside&lt;BR /&gt;pdm location PC5xxxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location TRIGOLDTESTPC 255.255.255.255 dmz&lt;BR /&gt;pdm location xxxxPC 255.255.255.255 inside&lt;BR /&gt;pdm location Keithxxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location KeithxxxxWirelessCard 255.255.255.255 inside&lt;BR /&gt;pdm location xxxxPC 255.255.255.255 inside&lt;BR /&gt;pdm location PC6xxxxPC 255.255.255.255 inside&lt;BR /&gt;pdm location xxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location TrainingRouter 255.255.255.255 dmz&lt;BR /&gt;pdm location xxx.16.0.248 255.255.255.248 outside&lt;BR /&gt;pdm location xxxxxxxPC32 255.255.255.255 inside&lt;BR /&gt;pdm location TelephonePABX 255.255.255.255 inside&lt;BR /&gt;pdm location TelephoneSupport 255.255.255.255 outside&lt;BR /&gt;pdm location LAPTOP31 255.255.255.255 inside&lt;BR /&gt;pdm location Server06-Exchange 255.255.255.255 inside&lt;BR /&gt;pdm location BlackspiderNew-4 255.255.224.0 outside&lt;BR /&gt;pdm location BlackspiderNew-3 255.255.248.0 outside&lt;BR /&gt;pdm location BlackspiderNew-1 255.255.248.0 outside&lt;BR /&gt;pdm location BlackspiderNew2 255.255.248.0 outside&lt;BR /&gt;pdm location xxxxxxxLAPTOP 255.255.255.255 inside&lt;BR /&gt;pdm location Laptop34xxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location ProxyServer 255.255.255.255 inside&lt;BR /&gt;pdm location ProxyServer2 255.255.255.255 inside&lt;BR /&gt;pdm location xxxxxxxPC32-2 255.255.255.255 inside&lt;BR /&gt;pdm location Webmail 255.255.255.255 outside&lt;BR /&gt;pdm location SERVER13-13Exchange 255.255.255.255 inside&lt;BR /&gt;pdm location SERVER13-12Exchange 255.255.255.255 inside&lt;BR /&gt;pdm location PC38-Kay-Oblj 255.255.255.255 inside&lt;BR /&gt;pdm location 192.168.0.80 255.255.255.255 inside&lt;BR /&gt;pdm group FTPAccess inside&lt;BR /&gt;pdm group ITExtendedAccess inside&lt;BR /&gt;pdm group ExchangeServers inside&lt;BR /&gt;pdm group OWAServers inside&lt;BR /&gt;pdm logging warnings 200&lt;BR /&gt;pdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;BR /&gt;nat (inside) 1 192.168.0.0 255.255.255.0 0 0&lt;BR /&gt;nat (dmz) 0 access-list dmz_outbound_nat0_acl&lt;BR /&gt;static (inside,outside) Mail-Outside Server01-Mail-Inside netmask 255.255.255.255 0 0 &lt;BR /&gt;static (dmz,outside) xxx.109.xxx.164 OWA netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) Webmail Server06-Exchange netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,dmz) Server01-Mail-Inside Server01-Mail-Inside netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,dmz) Server03-Safeword Server03-Safeword netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,dmz) Server06-Exchange Server06-Exchange netmask 255.255.255.255 0 0 &lt;BR /&gt;static (dmz,outside) xxx.109.xxx.165 TRIGOLDTESTPC netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) TelephonePABX TelephonePABX netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) xx.109.xxx.170 SERVER13-13Exchange netmask 255.255.255.255 0 0 &lt;BR /&gt;access-group outside in interface outside&lt;BR /&gt;access-group inside in interface inside&lt;BR /&gt;access-group dmz_access_in in interface dmz&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 xx.109.xxx.161 1&lt;BR /&gt;route inside SERVER13-13Exchange 255.255.255.255 Webmail 1&lt;BR /&gt;route inside TelephonePABX 255.255.255.255 xx.109.xxx.162 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;BR /&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;BR /&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;BR /&gt;timeout uauth 0:05:00 absolute&lt;BR /&gt;ntp server Server01-Mail-Inside source inside&lt;BR /&gt;http server enable&lt;BR /&gt;http CNS-Management1 255.255.255.240 outside&lt;BR /&gt;http CNS-Management2 255.255.255.240 outside&lt;BR /&gt;http xxxx_Home 255.255.255.255 outside&lt;BR /&gt;http Enterprise 255.255.255.255 outside&lt;BR /&gt;http Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;http Server01-Mail-Inside 255.255.255.255 inside&lt;BR /&gt;http Server02-File-Virus 255.255.255.255 inside&lt;BR /&gt;http xxxxxxxxxPC31 255.255.255.255 inside&lt;BR /&gt;http 192.168.0.80 255.255.255.255 inside&lt;BR /&gt;http xxxxxxx 255.255.255.255 inside&lt;BR /&gt;tftp-server inside Server03-Safeword /PIX&lt;BR /&gt;floodguard enable&lt;BR /&gt;sysopt connection permit-ipsec&lt;BR /&gt;telnet xxxxxxxxPC31 255.255.255.255 inside&lt;BR /&gt;telnet Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;telnet 192.168.0.80 255.255.255.255 inside&lt;BR /&gt;telnet xxxxPC 255.255.255.255 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh CNS-Management1 255.255.255.240 outside&lt;BR /&gt;ssh CNS-Management2 255.255.255.240 outside&lt;BR /&gt;ssh Enterprise 255.255.255.255 outside&lt;BR /&gt;ssh Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;ssh xxxxxxPC31 255.255.255.255 inside&lt;BR /&gt;ssh xxxxxx 255.255.255.255 inside&lt;BR /&gt;ssh timeout 10&lt;BR /&gt;console timeout 25&lt;BR /&gt;terminal width 80&lt;BR /&gt;: end&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:45:38 GMT</pubDate>
    <dc:creator>jcnewman83</dc:creator>
    <dc:date>2019-03-11T16:45:38Z</dc:date>
    <item>
      <title>PIX OWA Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321767#M807076</link>
      <description>&lt;P&gt;I am a newby here so please go easy on me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to set up my PIX to allow OWA access so basically all I need is port 443 open to a particular server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have included the PIX config below and was wondering if someone could help point me in the right direction? I though that a line that read something like: access-list inside permit ip host SERVER13-13Exchange any&lt;/P&gt;&lt;P&gt;would have done the trick but obviously I am mistaken, can anyone help? I have just taken over this pix so if you guys spot anything blindingly obvious wrong with my config a heads up would be appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of firewall command: "sh run"&lt;BR /&gt; &lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;PIX Version 6.3(5)&lt;BR /&gt;interface ethernet0 auto&lt;BR /&gt;interface ethernet1 auto&lt;BR /&gt;interface ethernet2 auto&lt;BR /&gt;nameif ethernet0 outside security0&lt;BR /&gt;nameif ethernet1 inside security100&lt;BR /&gt;nameif ethernet2 dmz security50&lt;BR /&gt;fixup protocol dns maximum-length 512&lt;BR /&gt;fixup protocol ftp 21&lt;BR /&gt;fixup protocol h323 h225 1720&lt;BR /&gt;fixup protocol h323 ras 1718-1719&lt;BR /&gt;fixup protocol http 80&lt;BR /&gt;fixup protocol rsh 514&lt;BR /&gt;fixup protocol rtsp 554&lt;BR /&gt;fixup protocol sip 5060&lt;BR /&gt;fixup protocol sip udp 5060&lt;BR /&gt;fixup protocol skinny 2000&lt;BR /&gt;fixup protocol smtp 25&lt;BR /&gt;fixup protocol sqlnet 1521&lt;BR /&gt;fixup protocol tftp 69&lt;BR /&gt;names&lt;BR /&gt;name xx.xxx.xxx.xxx Mail-Outside&lt;BR /&gt;name xx.x.x.x OWA&lt;BR /&gt;name xx.xxx.xx.xx CNS-Management1&lt;BR /&gt;name xxx.xxx.xxx.xx CNS-Management2&lt;BR /&gt;name xx.xxx.xxx.xx Mat_Home&lt;BR /&gt;name xxx.xx.xx.xxx Spider-net1&lt;BR /&gt;name xxx.xx.xx.xxx Spider-net2&lt;BR /&gt;name xxx.xxx.xxx.xx Enterprise&lt;BR /&gt;name 192.168.0.108 SamCorbynPC7&lt;BR /&gt;name 192.168.0.103 JoPC4FTP&lt;BR /&gt;name 192.168.0.111 PC5SamBaldwin&lt;BR /&gt;name 10.0.0.3 TRIGOLDTESTPC&lt;BR /&gt;name 192.168.0.102 JohnyPC&lt;BR /&gt;name 192.168.0.150 KeithBaldwinLaptop&lt;BR /&gt;name 192.168.0.151 KeithBaldwinWirelessCard&lt;BR /&gt;name 192.168.0.122 TishPC&lt;BR /&gt;name 192.168.0.120 PC6HelenPatersonPC&lt;BR /&gt;name 192.168.0.7 SimonHinsleyPC31&lt;BR /&gt;name 192.168.0.117 MartinMiles&lt;BR /&gt;name 10.0.0.4 TrainingRouter&lt;BR /&gt;name 192.168.0.133 PC26-Nicki-FTP-Access&lt;BR /&gt;name 192.168.0.3 Server02-File-Virus&lt;BR /&gt;name 192.168.0.2 Server01-Mail-Inside&lt;BR /&gt;name 192.168.0.4 Server03-Safeword&lt;BR /&gt;name 192.168.0.115 KirstyHartleyPC32&lt;BR /&gt;name 10.0.0.1 TelephoneSupport&lt;BR /&gt;name 192.168.0.35 TelephonePABX&lt;BR /&gt;name 192.168.0.154 LAPTOP31&lt;BR /&gt;name xxx.xx.232.0 BlackspiderNew2&lt;BR /&gt;name xx.xxx.32.0 BlackspiderNew-4&lt;BR /&gt;name xxx.xxx.216.0 BlackspiderNew-3&lt;BR /&gt;name xxx.50.xx.0 BlackspiderNew-1&lt;BR /&gt;name 192.168.0.136 DEBBIELAPTOP&lt;BR /&gt;name 192.168.0.168 Laptop34Kateb&lt;BR /&gt;name 192.168.0.8 Server06-Exchange&lt;BR /&gt;name 192.168.0.34 ProxyServer&lt;BR /&gt;name 192.168.0.33 ProxyServer2&lt;BR /&gt;name 192.168.0.19 KirstyHartleyPC32-2&lt;BR /&gt;name xx.109.xxx.166 Webmail&lt;BR /&gt;name 192.168.0.13 SERVER13-13Exchange&lt;BR /&gt;name 192.168.0.12 SERVER13-12Exchange&lt;BR /&gt;name 192.168.0.18 PC38-Kay-Oblj&lt;BR /&gt;object-group service ExchangeDMZTCP tcp &lt;BR /&gt;&amp;nbsp; description TCP ports used by Exchange Front to Back End&lt;BR /&gt;&amp;nbsp; port-object eq ldap &lt;BR /&gt;&amp;nbsp; port-object eq 691 &lt;BR /&gt;&amp;nbsp; port-object eq www &lt;BR /&gt;&amp;nbsp; port-object eq 88 &lt;BR /&gt;&amp;nbsp; port-object eq 3268 &lt;BR /&gt;&amp;nbsp; port-object eq domain &lt;BR /&gt;&amp;nbsp; port-object eq 135 &lt;BR /&gt;&amp;nbsp; port-object eq 5001 &lt;BR /&gt;object-group service ExchangeDMZUDP udp &lt;BR /&gt;&amp;nbsp; description UDP ports used by Exchange Front to Back End&lt;BR /&gt;&amp;nbsp; port-object eq 389 &lt;BR /&gt;&amp;nbsp; port-object eq 88 &lt;BR /&gt;&amp;nbsp; port-object eq domain &lt;BR /&gt;&amp;nbsp; port-object eq 691 &lt;BR /&gt;&amp;nbsp; port-object eq 3268 &lt;BR /&gt;&amp;nbsp; port-object eq 2833 &lt;BR /&gt;object-group service AddMail2OWA tcp &lt;BR /&gt;&amp;nbsp; port-object eq 137 &lt;BR /&gt;&amp;nbsp; port-object eq 135 &lt;BR /&gt;&amp;nbsp; port-object eq 445 &lt;BR /&gt;object-group service AddOWAtoMail udp &lt;BR /&gt;&amp;nbsp; port-object eq netbios-ns &lt;BR /&gt;object-group service AddOWAtoMailTCP tcp &lt;BR /&gt;&amp;nbsp; port-object eq 445 &lt;BR /&gt;&amp;nbsp; port-object eq netbios-ssn &lt;BR /&gt;&amp;nbsp; port-object eq https &lt;BR /&gt;object-group service TerminalService tcp &lt;BR /&gt;&amp;nbsp; description Terminal Services for Access Sorce Server&lt;BR /&gt;&amp;nbsp; port-object eq 3389 &lt;BR /&gt;&amp;nbsp; port-object eq ssh &lt;BR /&gt;object-group service CiscoVPN udp &lt;BR /&gt;&amp;nbsp; description Cisco Outbound UDP Ports 10000 4500 500&lt;BR /&gt;&amp;nbsp; port-object range isakmp isakmp &lt;BR /&gt;&amp;nbsp; port-object range 10000 10000 &lt;BR /&gt;&amp;nbsp; port-object range 4500 4500 &lt;BR /&gt;object-group network FTPAccess &lt;BR /&gt;&amp;nbsp; network-object xxPC4FTP 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxxPC7 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxPC31 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC5xxxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxPC 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC6xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC26 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object LAPTOP31 255.255.255.255 &lt;BR /&gt;object-group network ITExtendedAccess &lt;BR /&gt;&amp;nbsp; description Extended Access For IT PCs&lt;BR /&gt;&amp;nbsp; network-object xxxxxxxxPC31 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxPC32 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC38xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxPC32-2 255.255.255.255 &lt;BR /&gt;object-group service PhoneSystem tcp &lt;BR /&gt;&amp;nbsp; description Port 5000 For our Phones&lt;BR /&gt;&amp;nbsp; port-object range 5000 5000 &lt;BR /&gt;object-group service Remotebackup tcp &lt;BR /&gt;&amp;nbsp; port-object range 4401 4408 &lt;BR /&gt;object-group service TishWEBAccess tcp &lt;BR /&gt;&amp;nbsp; description Access For Tish For Web Admin&lt;BR /&gt;&amp;nbsp; port-object range 2222 2222 &lt;BR /&gt;&amp;nbsp; port-object range 50000 60000 &lt;BR /&gt;object-group service Https tcp &lt;BR /&gt;&amp;nbsp; description SERVER04 Access for All&lt;BR /&gt;&amp;nbsp; port-object eq https &lt;BR /&gt;&amp;nbsp; port-object eq 57483 &lt;BR /&gt;object-group service RemoteBackup udp &lt;BR /&gt;&amp;nbsp; port-object range 4401 4408 &lt;BR /&gt;object-group network ExchangeServers &lt;BR /&gt;&amp;nbsp; network-object Server01-Mail-Inside 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object Server06-Exchange 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object SERVER13-12Exchange 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object SERVER13-13Exchange 255.255.255.255 &lt;BR /&gt;object-group network OWAServers &lt;BR /&gt;&amp;nbsp; description Group to Allow OWA Services&lt;BR /&gt;&amp;nbsp; network-object SERVER13-13Exchange 255.255.255.255 &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (Live)&lt;BR /&gt;access-list outside permit tcp host Spider-net1 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (Live)&lt;BR /&gt;access-list outside permit tcp host Spider-net2 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew-1 255.255.248.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew2 255.255.248.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew-3 255.255.248.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew-4 255.255.224.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside deny ip host Enterprise host Mail-Outside &lt;BR /&gt;access-list outside remark Simon Web Publishing test&lt;BR /&gt;access-list outside permit tcp any eq www host Webmail eq www &lt;BR /&gt;access-list outside remark Allow OWA Access&lt;BR /&gt;access-list outside permit tcp any host xx.109.xxx.164 eq https &lt;BR /&gt;access-list outside remark Alow Terminal Services Access&lt;BR /&gt;access-list outside permit tcp any host xx.109.xxx.165 &lt;BR /&gt;access-list outside permit tcp any eq https host xx.109.xxx.170 eq https &lt;BR /&gt;access-list inside remark Allow DNS&lt;BR /&gt;access-list inside permit udp host Server03-Safeword any eq domain &lt;BR /&gt;access-list inside remark Additonal ports required for OWA Access&lt;BR /&gt;access-list inside permit tcp host Server03-Safeword any object-group AddMail2OWA &lt;BR /&gt;access-list inside remark Blackberry SRP Communication&lt;BR /&gt;access-list inside permit tcp host Server03-Safeword any eq 3101 &lt;BR /&gt;access-list inside permit udp host Server01-Mail-Inside any eq domain &lt;BR /&gt;access-list inside remark Allow FTP for Anti-Virus&lt;BR /&gt;access-list inside permit tcp host Server02-File-Virus any eq ftp &lt;BR /&gt;access-list inside remark Allow HTTP&lt;BR /&gt;access-list inside permit tcp any any eq www &lt;BR /&gt;access-list inside remark Allow HTTPS&lt;BR /&gt;access-list inside permit tcp any any eq https &lt;BR /&gt;access-list inside remark changed for Mortgage Stream&lt;BR /&gt;access-list inside permit tcp object-group ITExtendedAccess any object-group TishWEBAccess &lt;BR /&gt;access-list inside remark Mail to Spidernet(Existing)&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside host Spider-net1 eq smtp &lt;BR /&gt;access-list inside remark Mail to Spidernet (Existing)&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside host Spider-net2 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew1&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew-1 255.255.248.0 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew2&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew2 255.255.248.0 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew3&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew-3 255.255.248.0 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew4&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew-4 255.255.224.0 eq smtp &lt;BR /&gt;access-list inside remark Ftp Access For All Recruitment&lt;BR /&gt;access-list inside permit tcp any any eq ftp &lt;BR /&gt;access-list inside remark Ftp Access For All Recruitment&lt;BR /&gt;access-list inside permit tcp object-group FTPAccess any eq ftp &lt;BR /&gt;access-list inside remark Terminal Services Access For Simon Hinsley PC For sorce Test Server&lt;BR /&gt;access-list inside permit tcp object-group ITExtendedAccess any object-group TerminalService &lt;BR /&gt;access-list inside permit udp object-group ITExtendedAccess object-group CiscoVPN any object-group CiscoVPN &lt;BR /&gt;access-list inside remark Keith Laptop Pop 3 Access&lt;BR /&gt;access-list inside permit tcp host KeithWirelessCard any eq pop3 &lt;BR /&gt;access-list inside remark Keith Wireless Card Access&lt;BR /&gt;access-list inside permit tcp host KeithWirelessCard any eq smtp &lt;BR /&gt;access-list inside permit icmp object-group ITExtendedAccess any &lt;BR /&gt;access-list inside remark Allow DNS For SERVER02&lt;BR /&gt;access-list inside permit udp host Server02-File-Virus any eq domain &lt;BR /&gt;access-list inside permit ip host Server06-Exchange any &lt;BR /&gt;access-list inside permit ip host SERVER13-12Exchange any &lt;BR /&gt;access-list inside permit ip host SERVER13-13Exchange any &lt;BR /&gt;access-list Admin_splitTunnelAcl permit ip 192.168.0.0 255.255.255.0 any &lt;BR /&gt;access-list Admin_splitTunnelAcl permit ip 10.0.0.0 255.255.255.0 any &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip 192.168.0.0 255.255.255.0 xx.16.0.0 255.255.255.0 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip host Server02-File-Virus xxx.16.0.0 255.255.255.0 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip host Server01-Mail-Inside xxx.16.0.0 255.255.255.0 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip 192.168.0.0 255.255.255.0 xxx.16.0.248 255.255.255.248 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip any 172.16.0.248 255.255.255.248 &lt;BR /&gt;access-list dmz_outbound_nat0_acl permit ip 10.0.0.0 255.255.255.0 xxx.16.0.0 255.255.255.0 &lt;BR /&gt;access-list dmz_outbound_nat0_acl permit ip 10.0.0.0 255.255.255.0 xxx.16.0.248 255.255.255.248 &lt;BR /&gt;access-list xxxxxx_splitTunnelAcl permit ip host Server02-File-Virus any &lt;BR /&gt;access-list xxxxxx_splitTunnelAcl permit ip host Server01-Mail-Inside any &lt;BR /&gt;access-list xxxxxx_splitTunnelAcl permit ip host Server03-Safeword any &lt;BR /&gt;access-list dmz_access_in permit tcp host OWA host Server01-Mail-Inside object-group ExchangeDMZTCP &lt;BR /&gt;access-list dmz_access_in permit tcp host OWA host Server03-Safeword object-group ExchangeDMZTCP &lt;BR /&gt;access-list dmz_access_in remark Unmentioned ports&lt;BR /&gt;access-list dmz_access_in permit icmp host OWA host Server03-Safeword &lt;BR /&gt;access-list dmz_access_in remark Unmentioned ports&lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server03-Safeword object-group AddOWAtoMail &lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server01-Mail-Inside object-group ExchangeDMZUDP &lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server03-Safeword object-group ExchangeDMZUDP &lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server06-Exchange object-group ExchangeDMZUDP &lt;BR /&gt;access-list dmz_access_in remark Allow OWA server to get windows updates&lt;BR /&gt;access-list dmz_access_in permit tcp host OWA any eq www &lt;BR /&gt;access-list dmz_access_in remark &lt;BR /&gt;access-list dmz_access_in permit tcp host OWA any eq https &lt;BR /&gt;access-list dmz_access_in permit udp host OWA any eq domain &lt;BR /&gt;access-list dmz_access_in remark Bug Tracker https Access for the office&lt;BR /&gt;access-list dmz_access_in permit tcp host OWA any object-group AddOWAtoMailTCP &lt;BR /&gt;access-list dmz_access_in deny tcp host TRIGOLDTESTPC any &lt;BR /&gt;access-list dmz_access_in deny udp host TRIGOLDTESTPC any &lt;BR /&gt;access-list dmz_access_in deny icmp host TRIGOLDTESTPC any &lt;BR /&gt;access-list dmz_access_in deny ip host TRIGOLDTESTPC any &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging on&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging host inside Server03-Safeword&lt;BR /&gt;no logging message 710005&lt;BR /&gt;icmp deny any outside&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu dmz 1500&lt;BR /&gt;ip address outside xx.109.xxx.162 255.255.255.240&lt;BR /&gt;ip address inside 192.168.0.1 255.255.255.0&lt;BR /&gt;ip address dmz TelephoneSupport 255.255.255.0&lt;BR /&gt;ip audit info action alarm&lt;BR /&gt;ip audit attack action alarm&lt;BR /&gt;ip local pool Admin-Pool xxx.16.0.250-xxx.16.0.254&lt;BR /&gt;ip local pool UsersPool xxx.16.0.1-xxx.16.0.249&lt;BR /&gt;pdm location Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;pdm location PC31 255.255.255.255 inside&lt;BR /&gt;pdm location OWA 255.255.255.255 inside&lt;BR /&gt;pdm location Server01-Mail-Inside 255.255.255.255 inside&lt;BR /&gt;pdm location Server02-File-Virus 255.255.255.255 inside&lt;BR /&gt;pdm location OWA 255.255.255.255 dmz&lt;BR /&gt;pdm location 172.16.0.0 255.255.255.0 outside&lt;BR /&gt;pdm location CNS-Management1 255.255.255.240 outside&lt;BR /&gt;pdm location CNS-Management2 255.255.255.240 outside&lt;BR /&gt;pdm location xx.109.xxx.16 255.255.255.240 outside&lt;BR /&gt;pdm location xxx.16.0.1 255.255.255.255 outside&lt;BR /&gt;pdm location 192.168.0.132 255.255.255.255 inside&lt;BR /&gt;pdm location PC26xxxxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location Mat_Home 255.255.255.255 outside&lt;BR /&gt;pdm location Spider-net1 255.255.255.255 outside&lt;BR /&gt;pdm location Spider-net2 255.255.255.255 outside&lt;BR /&gt;pdm location Enterprise 255.255.255.255 outside&lt;BR /&gt;pdm location xxx.205.117.82 255.255.255.255 outside&lt;BR /&gt;pdm location xxx.158.73.44 255.255.255.255 outside&lt;BR /&gt;pdm location xxxxxxPC7 255.255.255.255 inside&lt;BR /&gt;pdm location xxPC4FTP 255.255.255.255 inside&lt;BR /&gt;pdm location PC5xxxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location TRIGOLDTESTPC 255.255.255.255 dmz&lt;BR /&gt;pdm location xxxxPC 255.255.255.255 inside&lt;BR /&gt;pdm location Keithxxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location KeithxxxxWirelessCard 255.255.255.255 inside&lt;BR /&gt;pdm location xxxxPC 255.255.255.255 inside&lt;BR /&gt;pdm location PC6xxxxPC 255.255.255.255 inside&lt;BR /&gt;pdm location xxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location TrainingRouter 255.255.255.255 dmz&lt;BR /&gt;pdm location xxx.16.0.248 255.255.255.248 outside&lt;BR /&gt;pdm location xxxxxxxPC32 255.255.255.255 inside&lt;BR /&gt;pdm location TelephonePABX 255.255.255.255 inside&lt;BR /&gt;pdm location TelephoneSupport 255.255.255.255 outside&lt;BR /&gt;pdm location LAPTOP31 255.255.255.255 inside&lt;BR /&gt;pdm location Server06-Exchange 255.255.255.255 inside&lt;BR /&gt;pdm location BlackspiderNew-4 255.255.224.0 outside&lt;BR /&gt;pdm location BlackspiderNew-3 255.255.248.0 outside&lt;BR /&gt;pdm location BlackspiderNew-1 255.255.248.0 outside&lt;BR /&gt;pdm location BlackspiderNew2 255.255.248.0 outside&lt;BR /&gt;pdm location xxxxxxxLAPTOP 255.255.255.255 inside&lt;BR /&gt;pdm location Laptop34xxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location ProxyServer 255.255.255.255 inside&lt;BR /&gt;pdm location ProxyServer2 255.255.255.255 inside&lt;BR /&gt;pdm location xxxxxxxPC32-2 255.255.255.255 inside&lt;BR /&gt;pdm location Webmail 255.255.255.255 outside&lt;BR /&gt;pdm location SERVER13-13Exchange 255.255.255.255 inside&lt;BR /&gt;pdm location SERVER13-12Exchange 255.255.255.255 inside&lt;BR /&gt;pdm location PC38-Kay-Oblj 255.255.255.255 inside&lt;BR /&gt;pdm location 192.168.0.80 255.255.255.255 inside&lt;BR /&gt;pdm group FTPAccess inside&lt;BR /&gt;pdm group ITExtendedAccess inside&lt;BR /&gt;pdm group ExchangeServers inside&lt;BR /&gt;pdm group OWAServers inside&lt;BR /&gt;pdm logging warnings 200&lt;BR /&gt;pdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;BR /&gt;nat (inside) 1 192.168.0.0 255.255.255.0 0 0&lt;BR /&gt;nat (dmz) 0 access-list dmz_outbound_nat0_acl&lt;BR /&gt;static (inside,outside) Mail-Outside Server01-Mail-Inside netmask 255.255.255.255 0 0 &lt;BR /&gt;static (dmz,outside) xxx.109.xxx.164 OWA netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) Webmail Server06-Exchange netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,dmz) Server01-Mail-Inside Server01-Mail-Inside netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,dmz) Server03-Safeword Server03-Safeword netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,dmz) Server06-Exchange Server06-Exchange netmask 255.255.255.255 0 0 &lt;BR /&gt;static (dmz,outside) xxx.109.xxx.165 TRIGOLDTESTPC netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) TelephonePABX TelephonePABX netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) xx.109.xxx.170 SERVER13-13Exchange netmask 255.255.255.255 0 0 &lt;BR /&gt;access-group outside in interface outside&lt;BR /&gt;access-group inside in interface inside&lt;BR /&gt;access-group dmz_access_in in interface dmz&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 xx.109.xxx.161 1&lt;BR /&gt;route inside SERVER13-13Exchange 255.255.255.255 Webmail 1&lt;BR /&gt;route inside TelephonePABX 255.255.255.255 xx.109.xxx.162 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;BR /&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;BR /&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;BR /&gt;timeout uauth 0:05:00 absolute&lt;BR /&gt;ntp server Server01-Mail-Inside source inside&lt;BR /&gt;http server enable&lt;BR /&gt;http CNS-Management1 255.255.255.240 outside&lt;BR /&gt;http CNS-Management2 255.255.255.240 outside&lt;BR /&gt;http xxxx_Home 255.255.255.255 outside&lt;BR /&gt;http Enterprise 255.255.255.255 outside&lt;BR /&gt;http Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;http Server01-Mail-Inside 255.255.255.255 inside&lt;BR /&gt;http Server02-File-Virus 255.255.255.255 inside&lt;BR /&gt;http xxxxxxxxxPC31 255.255.255.255 inside&lt;BR /&gt;http 192.168.0.80 255.255.255.255 inside&lt;BR /&gt;http xxxxxxx 255.255.255.255 inside&lt;BR /&gt;tftp-server inside Server03-Safeword /PIX&lt;BR /&gt;floodguard enable&lt;BR /&gt;sysopt connection permit-ipsec&lt;BR /&gt;telnet xxxxxxxxPC31 255.255.255.255 inside&lt;BR /&gt;telnet Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;telnet 192.168.0.80 255.255.255.255 inside&lt;BR /&gt;telnet xxxxPC 255.255.255.255 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh CNS-Management1 255.255.255.240 outside&lt;BR /&gt;ssh CNS-Management2 255.255.255.240 outside&lt;BR /&gt;ssh Enterprise 255.255.255.255 outside&lt;BR /&gt;ssh Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;ssh xxxxxxPC31 255.255.255.255 inside&lt;BR /&gt;ssh xxxxxx 255.255.255.255 inside&lt;BR /&gt;ssh timeout 10&lt;BR /&gt;console timeout 25&lt;BR /&gt;terminal width 80&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:45:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321767#M807076</guid>
      <dc:creator>jcnewman83</dc:creator>
      <dc:date>2019-03-11T16:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OWA Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321768#M807082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to allow https access from the outside you need to open the outside ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;You have "static (inside,outside) xx.109.xxx.170 SERVER13-13Exchange netmask 255.255.255.255 0 " so what you would need to open is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list outside permit tcp any host 109.xxx.170 eq 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I believe that will do the trick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Dec 2009 19:09:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321768#M807082</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-12-04T19:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OWA Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321769#M807086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK I have tried the rule you mention above but it has had no effect, I get nothing when I try to access the site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have confirmed the line (ccess-list outside permit tcp any host 109.xxx.170 eq 443.) is now in my config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Dec 2009 10:04:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321769#M807086</guid>
      <dc:creator>jcnewman83</dc:creator>
      <dc:date>2009-12-07T10:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OWA Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321770#M807091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK strike that, I have managed to get it working, I am however baffled on how I managed it, the machine in question has two network cards, 192.168.0.12 and 192.168.0.13&lt;/P&gt;&lt;P&gt;I was using the .12 address for internal and .13 for the external to get the webmail working I had to make a static route for 192.168.0.12 to xx.xxx.xxx.170 and set an access rule to allow ssl traffic to the .13 address. now I thought that simply changing everything including the static route to the .13 address would also work however it breaks it when I change the static route from .12 to .13 ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am a complete newby to the PIXs but what am I missing here?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Dec 2009 12:23:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321770#M807091</guid>
      <dc:creator>jcnewman83</dc:creator>
      <dc:date>2009-12-07T12:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OWA Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321771#M807095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I didn't get exactly what you did to make it work. I got up to the dual nics for the server part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the config you put it to make it work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Panos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Dec 2009 13:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321771#M807095</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-12-07T13:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OWA Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321772#M807099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no point really in having multiple IP's on your server since you're doing the static on the ASA anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution that pkampana posted earlier is the right way to do it. Basically to publish a server on the net (on a public ip) what you need is two things;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. A static nat statement&lt;/P&gt;&lt;P&gt;2. An ACL entry on your outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So something like..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 93.155.43.232 192.168.1.232 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list ACL-OUTSIDE extended permit tcp any host 93.155.43.232 eq 443 log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is all there is to it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Dec 2009 14:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321772#M807099</guid>
      <dc:creator>Kent Heide</dc:creator>
      <dc:date>2009-12-07T14:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OWA Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321773#M807103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;of corse:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of firewall command: "sh run"&lt;BR /&gt; &lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;PIX Version 6.3(5)&lt;BR /&gt;interface ethernet0 auto&lt;BR /&gt;interface ethernet1 auto&lt;BR /&gt;interface ethernet2 auto&lt;BR /&gt;nameif ethernet0 outside security0&lt;BR /&gt;nameif ethernet1 inside security100&lt;BR /&gt;nameif ethernet2 dmz security50&lt;BR /&gt;hostname pix&lt;BR /&gt;domain-name xxxxxxxxxxxx.co.uk&lt;BR /&gt;clock timezone GMT/BST 0&lt;BR /&gt;clock summer-time GMT/BDT recurring last Sun Mar 1:00 last Sun Oct 2:00&lt;BR /&gt;fixup protocol dns maximum-length 512&lt;BR /&gt;fixup protocol ftp 21&lt;BR /&gt;fixup protocol h323 h225 1720&lt;BR /&gt;fixup protocol h323 ras 1718-1719&lt;BR /&gt;fixup protocol http 80&lt;BR /&gt;fixup protocol rsh 514&lt;BR /&gt;fixup protocol rtsp 554&lt;BR /&gt;fixup protocol sip 5060&lt;BR /&gt;fixup protocol sip udp 5060&lt;BR /&gt;fixup protocol skinny 2000&lt;BR /&gt;fixup protocol smtp 25&lt;BR /&gt;fixup protocol sqlnet 1521&lt;BR /&gt;fixup protocol tftp 69&lt;BR /&gt;names&lt;BR /&gt;name xx.109.xxx.163 Mail-Outside&lt;BR /&gt;name 10.0.0.2 OWA&lt;BR /&gt;name 217.158.73.32 CNS-Management1&lt;BR /&gt;name 212.158.220.96 CNS-Management2&lt;BR /&gt;name 82.133.126.35 Mat_Home&lt;BR /&gt;name 217.69.20.190 Spider-net1&lt;BR /&gt;name 217.79.216.190 Spider-net2&lt;BR /&gt;name 217.205.117.85 Enterprise&lt;BR /&gt;name 192.168.0.108 PC7&lt;BR /&gt;name 192.168.0.103 PC4FTP&lt;BR /&gt;name 192.168.0.111 PC5&lt;BR /&gt;name 10.0.0.3 TRIGOLDTESTPC&lt;BR /&gt;name 192.168.0.102 xxxxxx&lt;BR /&gt;name 192.168.0.150 KBLaptop&lt;BR /&gt;name 192.168.0.151 KBWirelessCard&lt;BR /&gt;name 192.168.0.122 PC423423&lt;BR /&gt;name 192.168.0.120 PC6&lt;BR /&gt;name 192.168.0.7 xxxxxxPC31&lt;BR /&gt;name 192.168.0.117 user1234&lt;BR /&gt;name 10.0.0.4 TrainingRouter&lt;BR /&gt;name 192.168.0.133 PC26FTP&lt;BR /&gt;name 192.168.0.3 Server02-File-Virus&lt;BR /&gt;name 192.168.0.2 Server01-Mail-Inside&lt;BR /&gt;name 192.168.0.4 Server03-Safeword&lt;BR /&gt;name 192.168.0.115 xxxxxx&lt;BR /&gt;name 10.0.0.1 TelephoneSupport&lt;BR /&gt;name 192.168.0.35 TelephonePABX&lt;BR /&gt;name 192.168.0.154 LAPTOP31&lt;BR /&gt;name 208.87.232.0 BlackspiderNew2&lt;BR /&gt;name 85.115.32.0 BlackspiderNew-4&lt;BR /&gt;name 86.111.216.0 BlackspiderNew-3&lt;BR /&gt;name 116.50.56.0 BlackspiderNew-1&lt;BR /&gt;name 192.168.0.136 LAPTOP&lt;BR /&gt;name 192.168.0.168 Laptop34&lt;BR /&gt;name 192.168.0.8 Server06-Exchange&lt;BR /&gt;name 192.168.0.34 ProxyServer&lt;BR /&gt;name 192.168.0.33 ProxyServer2&lt;BR /&gt;name 192.168.0.19 xxxxxx-2&lt;BR /&gt;name xx.109.xxx.166 Webmail&lt;BR /&gt;name 192.168.0.13 SERVER13-13Exchange&lt;BR /&gt;name 192.168.0.12 SERVER13-12Exchange&lt;BR /&gt;name 192.168.0.18 PC38-xxxxxx&lt;BR /&gt;object-group service ExchangeDMZTCP tcp &lt;BR /&gt;&amp;nbsp; description TCP ports used by Exchange Front to Back End&lt;BR /&gt;&amp;nbsp; port-object eq ldap &lt;BR /&gt;&amp;nbsp; port-object eq 691 &lt;BR /&gt;&amp;nbsp; port-object eq www &lt;BR /&gt;&amp;nbsp; port-object eq 88 &lt;BR /&gt;&amp;nbsp; port-object eq 3268 &lt;BR /&gt;&amp;nbsp; port-object eq domain &lt;BR /&gt;&amp;nbsp; port-object eq 135 &lt;BR /&gt;&amp;nbsp; port-object eq 5001 &lt;BR /&gt;object-group service ExchangeDMZUDP udp &lt;BR /&gt;&amp;nbsp; description UDP ports used by Exchange Front to Back End&lt;BR /&gt;&amp;nbsp; port-object eq 389 &lt;BR /&gt;&amp;nbsp; port-object eq 88 &lt;BR /&gt;&amp;nbsp; port-object eq domain &lt;BR /&gt;&amp;nbsp; port-object eq 691 &lt;BR /&gt;&amp;nbsp; port-object eq 3268 &lt;BR /&gt;&amp;nbsp; port-object eq 2833 &lt;BR /&gt;object-group service AddMail2OWA tcp &lt;BR /&gt;&amp;nbsp; port-object eq 137 &lt;BR /&gt;&amp;nbsp; port-object eq 135 &lt;BR /&gt;&amp;nbsp; port-object eq 445 &lt;BR /&gt;object-group service AddOWAtoMail udp &lt;BR /&gt;&amp;nbsp; port-object eq netbios-ns &lt;BR /&gt;object-group service AddOWAtoMailTCP tcp &lt;BR /&gt;&amp;nbsp; port-object eq 445 &lt;BR /&gt;&amp;nbsp; port-object eq netbios-ssn &lt;BR /&gt;&amp;nbsp; port-object eq https &lt;BR /&gt;object-group service TerminalService tcp &lt;BR /&gt;&amp;nbsp; description Terminal Services for Access Sorce Server&lt;BR /&gt;&amp;nbsp; port-object eq 3389 &lt;BR /&gt;&amp;nbsp; port-object eq ssh &lt;BR /&gt;object-group service CiscoVPN udp &lt;BR /&gt;&amp;nbsp; description Cisco Outbound UDP Ports 10000 4500 500&lt;BR /&gt;&amp;nbsp; port-object range isakmp isakmp &lt;BR /&gt;&amp;nbsp; port-object range 10000 10000 &lt;BR /&gt;&amp;nbsp; port-object range 4500 4500 &lt;BR /&gt;object-group network FTPAccess &lt;BR /&gt;&amp;nbsp; network-object PC4FTP 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC7 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxxPC31 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC5 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC6 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC26FTP 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object LAPTOP31 255.255.255.255 &lt;BR /&gt;object-group network ITExtendedAccess &lt;BR /&gt;&amp;nbsp; description Extended Access For IT PCs&lt;BR /&gt;&amp;nbsp; network-object xxxxxxPC31 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC423423 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object user1234 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object PC38-xxxxxx 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object LAPTOP 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object Laptop34 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object ProxyServer 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object ProxyServer2 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object xxxxxx-2 255.255.255.255 &lt;BR /&gt;object-group service PhoneSystem tcp &lt;BR /&gt;&amp;nbsp; description Port 5000 For our Phones&lt;BR /&gt;&amp;nbsp; port-object range 5000 5000 &lt;BR /&gt;object-group service Remotebackup tcp &lt;BR /&gt;&amp;nbsp; port-object range 4401 4408 &lt;BR /&gt;object-group service TishWEBAccess tcp &lt;BR /&gt;&amp;nbsp; description Access For Tish For Web Admin&lt;BR /&gt;&amp;nbsp; port-object range 2222 2222 &lt;BR /&gt;&amp;nbsp; port-object range 50000 60000 &lt;BR /&gt;object-group service Https tcp &lt;BR /&gt;&amp;nbsp; description SERVER04 Access for All&lt;BR /&gt;&amp;nbsp; port-object eq https &lt;BR /&gt;&amp;nbsp; port-object eq 57483 &lt;BR /&gt;object-group service RemoteBackup udp &lt;BR /&gt;&amp;nbsp; port-object range 4401 4408 &lt;BR /&gt;object-group network ExchangeServers &lt;BR /&gt;&amp;nbsp; network-object Server01-Mail-Inside 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object Server06-Exchange 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object SERVER13-12Exchange 255.255.255.255 &lt;BR /&gt;&amp;nbsp; network-object SERVER13-13Exchange 255.255.255.255 &lt;BR /&gt;object-group network OWAServers &lt;BR /&gt;&amp;nbsp; description Group to Allow OWA Services&lt;BR /&gt;&amp;nbsp; network-object SERVER13-13Exchange 255.255.255.255 &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (Live)&lt;BR /&gt;access-list outside permit tcp host Spider-net1 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (Live)&lt;BR /&gt;access-list outside permit tcp host Spider-net2 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew-1 255.255.248.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew2 255.255.248.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew-3 255.255.248.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside remark Allow SMTP to Mailserver (New)&lt;BR /&gt;access-list outside permit tcp BlackspiderNew-4 255.255.224.0 host Mail-Outside eq smtp &lt;BR /&gt;access-list outside deny ip host Enterprise host Mail-Outside &lt;BR /&gt;access-list outside remark Web Publishing test&lt;BR /&gt;access-list outside permit tcp any eq www host Webmail eq www &lt;BR /&gt;access-list outside remark Allow OWA Access&lt;BR /&gt;access-list outside permit tcp any host xx.109.xxx.164 eq https &lt;BR /&gt;access-list outside remark Alow Terminal Services Access&lt;BR /&gt;access-list outside permit tcp any host xx.109.xxx.165 &lt;BR /&gt;access-list outside permit tcp any host xx.109.xxx.170 eq https &lt;BR /&gt;access-list inside remark Allow DNS&lt;BR /&gt;access-list inside permit udp host Server03-Safeword any eq domain &lt;BR /&gt;access-list inside remark Additonal ports required for OWA Access&lt;BR /&gt;access-list inside permit tcp host Server03-Safeword any object-group AddMail2OWA &lt;BR /&gt;access-list inside remark Blackberry SRP Communication&lt;BR /&gt;access-list inside permit tcp host Server03-Safeword any eq 3101 &lt;BR /&gt;access-list inside permit udp host Server01-Mail-Inside any eq domain &lt;BR /&gt;access-list inside remark Allow FTP for Anti-Virus&lt;BR /&gt;access-list inside permit tcp host Server02-File-Virus any eq ftp &lt;BR /&gt;access-list inside remark Allow HTTP&lt;BR /&gt;access-list inside permit tcp any any eq www &lt;BR /&gt;access-list inside remark Allow HTTPS&lt;BR /&gt;access-list inside permit tcp any any eq https &lt;BR /&gt;access-list inside remark changed for Mortgage Stream&lt;BR /&gt;access-list inside permit tcp object-group ITExtendedAccess any object-group TishWEBAccess &lt;BR /&gt;access-list inside remark Mail to Spidernet(Existing)&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside host Spider-net1 eq smtp &lt;BR /&gt;access-list inside remark Mail to Spidernet (Existing)&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside host Spider-net2 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew1&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew-1 255.255.248.0 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew2&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew2 255.255.248.0 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew3&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew-3 255.255.248.0 eq smtp &lt;BR /&gt;access-list inside remark BlackspiderNew4&lt;BR /&gt;access-list inside permit tcp host Server01-Mail-Inside BlackspiderNew-4 255.255.224.0 eq smtp &lt;BR /&gt;access-list inside remark Ftp Access For All Recruitment&lt;BR /&gt;access-list inside permit tcp any any eq ftp &lt;BR /&gt;access-list inside remark Ftp Access For All Recruitment&lt;BR /&gt;access-list inside permit tcp object-group FTPAccess any eq ftp &lt;BR /&gt;access-list inside remark Terminal Services Access For PC For sorce Test Server&lt;BR /&gt;access-list inside permit tcp object-group ITExtendedAccess any object-group TerminalService &lt;BR /&gt;access-list inside permit udp object-group ITExtendedAccess object-group CiscoVPN any object-group CiscoVPN &lt;BR /&gt;access-list inside remark Laptop Pop 3 Access&lt;BR /&gt;access-list inside permit tcp host KBWirelessCard any eq pop3 &lt;BR /&gt;access-list inside remark Wireless Card Access&lt;BR /&gt;access-list inside permit tcp host KBWirelessCard any eq smtp &lt;BR /&gt;access-list inside permit icmp object-group ITExtendedAccess any &lt;BR /&gt;access-list inside remark Allow DNS For SERVER02&lt;BR /&gt;access-list inside permit udp host Server02-File-Virus any eq domain &lt;BR /&gt;access-list inside permit ip host Server06-Exchange any &lt;BR /&gt;access-list inside permit ip host SERVER13-12Exchange any &lt;BR /&gt;access-list inside permit ip host SERVER13-13Exchange any &lt;BR /&gt;access-list Admin_splitTunnelAcl permit ip 192.168.0.0 255.255.255.0 any &lt;BR /&gt;access-list Admin_splitTunnelAcl permit ip 10.0.0.0 255.255.255.0 any &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip 192.168.0.0 255.255.255.0 172.16.0.0 255.255.255.0 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip host Server02-File-Virus 172.16.0.0 255.255.255.0 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip host Server01-Mail-Inside 172.16.0.0 255.255.255.0 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip 192.168.0.0 255.255.255.0 172.16.0.248 255.255.255.248 &lt;BR /&gt;access-list inside_outbound_nat0_acl permit ip any 172.16.0.248 255.255.255.248 &lt;BR /&gt;access-list dmz_outbound_nat0_acl permit ip 10.0.0.0 255.255.255.0 172.16.0.0 255.255.255.0 &lt;BR /&gt;access-list dmz_outbound_nat0_acl permit ip 10.0.0.0 255.255.255.0 172.16.0.248 255.255.255.248 &lt;BR /&gt;access-list HomeofChoice_splitTunnelAcl permit ip host Server02-File-Virus any &lt;BR /&gt;access-list HomeofChoice_splitTunnelAcl permit ip host Server01-Mail-Inside any &lt;BR /&gt;access-list HomeofChoice_splitTunnelAcl permit ip host Server03-Safeword any &lt;BR /&gt;access-list dmz_access_in permit tcp host OWA host Server01-Mail-Inside object-group ExchangeDMZTCP &lt;BR /&gt;access-list dmz_access_in permit tcp host OWA host Server03-Safeword object-group ExchangeDMZTCP &lt;BR /&gt;access-list dmz_access_in remark Unmentioned ports&lt;BR /&gt;access-list dmz_access_in permit icmp host OWA host Server03-Safeword &lt;BR /&gt;access-list dmz_access_in remark Unmentioned ports&lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server03-Safeword object-group AddOWAtoMail &lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server01-Mail-Inside object-group ExchangeDMZUDP &lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server03-Safeword object-group ExchangeDMZUDP &lt;BR /&gt;access-list dmz_access_in permit udp host OWA host Server06-Exchange object-group ExchangeDMZUDP &lt;BR /&gt;access-list dmz_access_in remark Allow OWA server to get windows updates&lt;BR /&gt;access-list dmz_access_in permit tcp host OWA any eq www &lt;BR /&gt;access-list dmz_access_in remark &lt;BR /&gt;access-list dmz_access_in permit tcp host OWA any eq https &lt;BR /&gt;access-list dmz_access_in permit udp host OWA any eq domain &lt;BR /&gt;access-list dmz_access_in remark Bug Tracker https Access for the office&lt;BR /&gt;access-list dmz_access_in permit tcp host OWA any object-group AddOWAtoMailTCP &lt;BR /&gt;access-list dmz_access_in deny tcp host TRIGOLDTESTPC any &lt;BR /&gt;access-list dmz_access_in deny udp host TRIGOLDTESTPC any &lt;BR /&gt;access-list dmz_access_in deny icmp host TRIGOLDTESTPC any &lt;BR /&gt;access-list dmz_access_in deny ip host TRIGOLDTESTPC any &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging on&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging host inside Server03-Safeword&lt;BR /&gt;no logging message 710005&lt;BR /&gt;icmp deny any outside&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu dmz 1500&lt;BR /&gt;ip address outside xx.109.xxx.162 255.255.255.240&lt;BR /&gt;ip address inside 192.168.0.1 255.255.255.0&lt;BR /&gt;ip address dmz TelephoneSupport 255.255.255.0&lt;BR /&gt;ip audit info action alarm&lt;BR /&gt;ip audit attack action alarm&lt;BR /&gt;pdm location Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;pdm location xxxxxxPC31 255.255.255.255 inside&lt;BR /&gt;pdm location OWA 255.255.255.255 inside&lt;BR /&gt;pdm location Server01-Mail-Inside 255.255.255.255 inside&lt;BR /&gt;pdm location Server02-File-Virus 255.255.255.255 inside&lt;BR /&gt;pdm location OWA 255.255.255.255 dmz&lt;BR /&gt;pdm location 172.16.0.0 255.255.255.0 outside&lt;BR /&gt;pdm location CNS-Management1 255.255.255.240 outside&lt;BR /&gt;pdm location CNS-Management2 255.255.255.240 outside&lt;BR /&gt;pdm location xx.109.xxx.16 255.255.255.240 outside&lt;BR /&gt;pdm location 172.16.0.1 255.255.255.255 outside&lt;BR /&gt;pdm location 192.168.0.132 255.255.255.255 inside&lt;BR /&gt;pdm location PC26FTP 255.255.255.255 inside&lt;BR /&gt;pdm location xxx_Home 255.255.255.255 outside&lt;BR /&gt;pdm location Spider-net1 255.255.255.255 outside&lt;BR /&gt;pdm location Spider-net2 255.255.255.255 outside&lt;BR /&gt;pdm location Enterprise 255.255.255.255 outside&lt;BR /&gt;pdm location 217.xxx.117.xx 255.255.255.255 outside&lt;BR /&gt;pdm location 217.xxx.73.xx 255.255.255.255 outside&lt;BR /&gt;pdm location PC7 255.255.255.255 inside&lt;BR /&gt;pdm location PC4FTP 255.255.255.255 inside&lt;BR /&gt;pdm location PC5 255.255.255.255 inside&lt;BR /&gt;pdm location TRIGOLDTESTPC 255.255.255.255 dmz&lt;BR /&gt;pdm location xxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location KBLaptop 255.255.255.255 inside&lt;BR /&gt;pdm location KBWirelessCard 255.255.255.255 inside&lt;BR /&gt;pdm location PC423423 255.255.255.255 inside&lt;BR /&gt;pdm location PC6 255.255.255.255 inside&lt;BR /&gt;pdm location user1234 255.255.255.255 inside&lt;BR /&gt;pdm location TrainingRouter 255.255.255.255 dmz&lt;BR /&gt;pdm location 172.16.0.248 255.255.255.248 outside&lt;BR /&gt;pdm location xxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location TelephonePABX 255.255.255.255 inside&lt;BR /&gt;pdm location TelephoneSupport 255.255.255.255 outside&lt;BR /&gt;pdm location LAPTOP31 255.255.255.255 inside&lt;BR /&gt;pdm location Server06-Exchange 255.255.255.255 inside&lt;BR /&gt;pdm location BlackspiderNew-4 255.255.224.0 outside&lt;BR /&gt;pdm location BlackspiderNew-3 255.255.248.0 outside&lt;BR /&gt;pdm location BlackspiderNew-1 255.255.248.0 outside&lt;BR /&gt;pdm location BlackspiderNew2 255.255.248.0 outside&lt;BR /&gt;pdm location LAPTOP 255.255.255.255 inside&lt;BR /&gt;pdm location Laptop34 255.255.255.255 inside&lt;BR /&gt;pdm location ProxyServer 255.255.255.255 inside&lt;BR /&gt;pdm location ProxyServer2 255.255.255.255 inside&lt;BR /&gt;pdm location xxxxxx-2 255.255.255.255 inside&lt;BR /&gt;pdm location Webmail 255.255.255.255 outside&lt;BR /&gt;pdm location SERVER13-13Exchange 255.255.255.255 inside&lt;BR /&gt;pdm location SERVER13-12Exchange 255.255.255.255 inside&lt;BR /&gt;pdm location PC38-xxxxxx 255.255.255.255 inside&lt;BR /&gt;pdm location 192.168.0.80 255.255.255.255 inside&lt;BR /&gt;pdm location xx.109.xxx.170 255.255.255.255 outside&lt;BR /&gt;pdm group FTPAccess inside&lt;BR /&gt;pdm group ITExtendedAccess inside&lt;BR /&gt;pdm group ExchangeServers inside&lt;BR /&gt;pdm group OWAServers inside&lt;BR /&gt;pdm logging warnings 200&lt;BR /&gt;pdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;BR /&gt;nat (inside) 1 192.168.0.0 255.255.255.0 0 0&lt;BR /&gt;nat (dmz) 0 access-list dmz_outbound_nat0_acl&lt;BR /&gt;static (inside,outside) Mail-Outside Server01-Mail-Inside netmask 255.255.255.255 0 0 &lt;BR /&gt;static (dmz,outside) xx.109.xxx.164 OWA netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) Webmail Server06-Exchange netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,dmz) Server01-Mail-Inside Server01-Mail-Inside netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,dmz) Server03-Safeword Server03-Safeword netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,dmz) Server06-Exchange Server06-Exchange netmask 255.255.255.255 0 0 &lt;BR /&gt;static (dmz,outside) xx.109.xxx.165 TRIGOLDTESTPC netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) TelephonePABX TelephonePABX netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) xx.109.xxx.170 SERVER13-13Exchange netmask 255.255.255.255 0 0 &lt;BR /&gt;access-group outside in interface outside&lt;BR /&gt;access-group inside in interface inside&lt;BR /&gt;access-group dmz_access_in in interface dmz&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 xx.109.xxx.161 1&lt;BR /&gt;route inside SERVER13-12Exchange 255.255.255.255 xx.109.xxx.170 1&lt;BR /&gt;route inside TelephonePABX 255.255.255.255 xx.109.xxx.162 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;BR /&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;BR /&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;BR /&gt;timeout uauth 0:05:00 absolute&lt;BR /&gt;ntp server Server01-Mail-Inside source inside&lt;BR /&gt;http server enable&lt;BR /&gt;http CNS-Management1 255.255.255.240 outside&lt;BR /&gt;http CNS-Management2 255.255.255.240 outside&lt;BR /&gt;http xxx_Home 255.255.255.255 outside&lt;BR /&gt;http Enterprise 255.255.255.255 outside&lt;BR /&gt;http Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;http Server01-Mail-Inside 255.255.255.255 inside&lt;BR /&gt;http Server02-File-Virus 255.255.255.255 inside&lt;BR /&gt;http xxxxxxPC31 255.255.255.255 inside&lt;BR /&gt;http 192.168.0.80 255.255.255.255 inside&lt;BR /&gt;http xxxxxx 255.255.255.255 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server community thisismyhomeofchoice&lt;BR /&gt;no snmp-server enable traps&lt;BR /&gt;tftp-server inside Server03-Safeword /PIX&lt;BR /&gt;floodguard enable&lt;BR /&gt;sysopt connection permit-ipsec&lt;BR /&gt;telnet xxxxxxPC31 255.255.255.255 inside&lt;BR /&gt;telnet Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;telnet 192.168.0.80 255.255.255.255 inside&lt;BR /&gt;telnet xxxxxx 255.255.255.255 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh CNS-Management1 255.255.255.240 outside&lt;BR /&gt;ssh CNS-Management2 255.255.255.240 outside&lt;BR /&gt;ssh Enterprise 255.255.255.255 outside&lt;BR /&gt;ssh Server03-Safeword 255.255.255.255 inside&lt;BR /&gt;ssh xxxxxxPC31 255.255.255.255 inside&lt;BR /&gt;ssh xxxxxx 255.255.255.255 inside&lt;BR /&gt;ssh timeout 10&lt;BR /&gt;console timeout 25&lt;BR /&gt;terminal width 80&lt;BR /&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Dec 2009 14:53:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321773#M807103</guid>
      <dc:creator>jcnewman83</dc:creator>
      <dc:date>2009-12-07T14:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX OWA Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321774#M807106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;name 192.168.0.13 SERVER13-13Exchange&lt;BR /&gt;name 192.168.0.12 SERVER13-12Exchange&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To allow outside people to reach you server on 443 from outside you need&lt;BR /&gt;- outside ACL to allow outside people to reach the xx.109.xxx.170 on that port&lt;BR /&gt;- a static translation for the global and local ip of the server&lt;BR /&gt;static (inside,outside) xx.109.xxx.170 SERVER13-13Exchange netmask 255.255.255.255 0 0&lt;BR /&gt;= A route to the local ip of the server so that the PIX can route to it&lt;BR /&gt;route inside SERVER13-13Exchange 255.255.255.255 Webmail 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, that is why it works with the above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now as for .12 it is used for inside people to use webmail so they will just talk to it locally without the PIX being involved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Dec 2009 15:29:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-owa-help/m-p/1321774#M807106</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-12-07T15:29:40Z</dc:date>
    </item>
  </channel>
</rss>

