<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Telnet through outside PIX interface? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109304#M894819</link>
    <description>&lt;P&gt;I have PIX 501 separating my two internal networks.&lt;/P&gt;&lt;P&gt;I am located on network A (10.80.48.0)on outside PIX interface. Server which I need to access is on network B (172.31.1.0)inside PIX interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is part of PIX config:&lt;/P&gt;&lt;P&gt;ip address outside 10.80.48.50 255.255.252.0&lt;/P&gt;&lt;P&gt;ip address inside 172.31.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name 172.31.1.2 SERVER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface ftp SERVER ftp netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list FromOutside permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This allows me to ftp from network A to SERVER on network B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I allow telnet (23) to SERVER from network A?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I replace static to:&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface telnet SERVER telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;then telnet is working but ftp is not.&lt;/P&gt;&lt;P&gt;How to make both ftp and telnet to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is log entries while I am trying to telnet from network A to SERVER (10.80.48.50) on network B:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Rec'd packet not an IPSEC packet. (ip) dest_addr= 10.80.48.50, src_addr= 10.80.48.47, prot= tcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would appreciate help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:59:37 GMT</pubDate>
    <dc:creator>amarula115</dc:creator>
    <dc:date>2019-03-11T13:59:37Z</dc:date>
    <item>
      <title>Telnet through outside PIX interface?</title>
      <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109304#M894819</link>
      <description>&lt;P&gt;I have PIX 501 separating my two internal networks.&lt;/P&gt;&lt;P&gt;I am located on network A (10.80.48.0)on outside PIX interface. Server which I need to access is on network B (172.31.1.0)inside PIX interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is part of PIX config:&lt;/P&gt;&lt;P&gt;ip address outside 10.80.48.50 255.255.252.0&lt;/P&gt;&lt;P&gt;ip address inside 172.31.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name 172.31.1.2 SERVER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface ftp SERVER ftp netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list FromOutside permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This allows me to ftp from network A to SERVER on network B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I allow telnet (23) to SERVER from network A?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I replace static to:&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface telnet SERVER telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;then telnet is working but ftp is not.&lt;/P&gt;&lt;P&gt;How to make both ftp and telnet to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is log entries while I am trying to telnet from network A to SERVER (10.80.48.50) on network B:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Rec'd packet not an IPSEC packet. (ip) dest_addr= 10.80.48.50, src_addr= 10.80.48.47, prot= tcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would appreciate help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:59:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109304#M894819</guid>
      <dc:creator>amarula115</dc:creator>
      <dc:date>2019-03-11T13:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet through outside PIX interface?</title>
      <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109305#M894824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason is that either you have mapped only FTP access or telnet access in the static entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Delete static nat nd use the following commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) interface SERVER netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope, it helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 05:10:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109305#M894824</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-10-20T05:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet through outside PIX interface?</title>
      <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109306#M894831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why are you 'replacing' the static?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just enter both at once:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface ftp SERVER ftp netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface telnet SERVER telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 06:07:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109306#M894831</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-20T06:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet through outside PIX interface?</title>
      <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109307#M894834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried and PIX doesn't accept two static to the same interface, one for ftp and one for telnet.&lt;/P&gt;&lt;P&gt;You can have only one or other&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 10:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109307#M894834</guid>
      <dc:creator>amarula115</dc:creator>
      <dc:date>2008-10-20T10:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet through outside PIX interface?</title>
      <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109308#M894836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to put only one command what I posted earlier then check its responding or not. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 11:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109308#M894836</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-10-20T11:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet through outside PIX interface?</title>
      <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109309#M894838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it helped when I entered &lt;/P&gt;&lt;P&gt;static (inside,outside) interface SERVER netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but right now I cannot ssh to the outside interface of the PIX. Outside interface is(10.80.48.50)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;before:&lt;/P&gt;&lt;P&gt;ssh to 10.80.48.50 - OK&lt;/P&gt;&lt;P&gt;ftp to 10.80.48.50 - OK&lt;/P&gt;&lt;P&gt;telnet to 10.80.48.50 - NOT OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now:&lt;/P&gt;&lt;P&gt;ftp to 10.80.48.50 - OK&lt;/P&gt;&lt;P&gt;telnet to 10.80.48.50 - OK&lt;/P&gt;&lt;P&gt;ssh to 10.80.48.50 - NOT OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will have to remove command I entered beause I need from time to time make changes on this PIX and I cannot access it anymore. Since it is located in remote location I need to have ssh access to it. I will ask someone from this location to reload the PIX so I will have an access to it again but then telnet will not work anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 11:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109309#M894838</guid>
      <dc:creator>amarula115</dc:creator>
      <dc:date>2008-10-20T11:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet through outside PIX interface?</title>
      <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109310#M894840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did the following:&lt;/P&gt;&lt;P&gt;no static (inside,outside) tcp interface ftp SERVER ftp netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) interface SERVER netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now ftp and telnet are working but I lost ssh access to the PIX as described in previous post&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 11:23:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109310#M894840</guid>
      <dc:creator>amarula115</dc:creator>
      <dc:date>2008-10-20T11:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet through outside PIX interface?</title>
      <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109311#M894841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you running 6.x code?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that this works on 7.x for sure...&lt;/P&gt;&lt;P&gt;The ASA will give you a 'warning' but it *will be* there when you do a 'show run static'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 11:51:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109311#M894841</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-20T11:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet through outside PIX interface?</title>
      <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109312#M894843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I run 6.3(4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) interface SERVER netmask 255.255.255.255 allowing telnet what I needed but cutting my access to PIX through ssh.&lt;/P&gt;&lt;P&gt;Any other way to allow telnet and ftp but still be able to ssh to PIX?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I somehow manually map ftp and telnet?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 12:08:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109312#M894843</guid>
      <dc:creator>amarula115</dc:creator>
      <dc:date>2008-10-20T12:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet through outside PIX interface?</title>
      <link>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109313#M894846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, As i think, it must be connect via SSH. I would advice you while you try to connect PIX through SSH and then check the logs nd see why it's blocking the SSH connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post your logs.&lt;/P&gt;&lt;P&gt;Hope it will help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 13:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-through-outside-pix-interface/m-p/1109313#M894846</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-10-20T13:21:10Z</dc:date>
    </item>
  </channel>
</rss>

