<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enabling https correctly for a Cisco PIX 506E in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/enabling-https-correctly-for-a-cisco-pix-506e/m-p/1178029#M840697</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answers.  You are correct, the proxy server is 10.10.10.2 and that I'm applying it in the inside interface; I have the same line for port 80.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"You could try to allow all out port 443"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please elaborate further on how you intend to do this?  Which commands for example are you referring to accomplish this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot and appreciate your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fidel  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 Jun 2009 00:19:24 GMT</pubDate>
    <dc:creator>bashan121</dc:creator>
    <dc:date>2009-06-01T00:19:24Z</dc:date>
    <item>
      <title>Enabling https correctly for a Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/enabling-https-correctly-for-a-cisco-pix-506e/m-p/1178027#M840695</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure I ran the correct acl permit statements to enable https on the Cisco PIX 506E.  I'm testing a proxy server which is connected to the Cisco PIX 506E.  From a browser, I'm able to successfully view web pages, however, for all https protocols, its being refused.  Are the ff two lines enough to open https traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp host 10.10.10.2 any eq 443&lt;/P&gt;&lt;P&gt;access-list acl-in permit udp host 10.10.10.2 any eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks much and appreciate any advice you could provide a newbie on PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fidel &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:37:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-https-correctly-for-a-cisco-pix-506e/m-p/1178027#M840695</guid>
      <dc:creator>bashan121</dc:creator>
      <dc:date>2019-03-11T15:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling https correctly for a Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/enabling-https-correctly-for-a-cisco-pix-506e/m-p/1178028#M840696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this is acl is applied on the inside interface, and you're allowing the host 10.10.10.2 out, then it should be enough. Do you have the same lines for port 80? You could try to allow all out port 443 and see if that fixes the issue as a test, and then narrow it down from there. I'm assuming that 10.10.10.2 is your proxy server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 May 2009 12:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-https-correctly-for-a-cisco-pix-506e/m-p/1178028#M840696</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-29T12:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling https correctly for a Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/enabling-https-correctly-for-a-cisco-pix-506e/m-p/1178029#M840697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answers.  You are correct, the proxy server is 10.10.10.2 and that I'm applying it in the inside interface; I have the same line for port 80.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"You could try to allow all out port 443"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please elaborate further on how you intend to do this?  Which commands for example are you referring to accomplish this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot and appreciate your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fidel  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jun 2009 00:19:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-https-correctly-for-a-cisco-pix-506e/m-p/1178029#M840697</guid>
      <dc:creator>bashan121</dc:creator>
      <dc:date>2009-06-01T00:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling https correctly for a Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/enabling-https-correctly-for-a-cisco-pix-506e/m-p/1178030#M840698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Fidel,&lt;/P&gt;&lt;P&gt;   PIX permits all traffic originated from inside interface by default, so you dont have to put any ACL statements. You dont have to enable https either, yet enabling https in PIX means you enable secure web access to PIX for administration (PDM)&lt;/P&gt;&lt;P&gt;   Assuming that you are using Internet Explorer in internet explorer options, click connections tab&amp;gt;lan settings&amp;gt;advanced and check "Use the same proxy server for all protocols" box. If not resolved, most probably thers something wrong with your proxy server configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jun 2009 00:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-https-correctly-for-a-cisco-pix-506e/m-p/1178030#M840698</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2009-06-01T00:53:27Z</dc:date>
    </item>
  </channel>
</rss>

