<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with PIX configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096604#M896335</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Either way will work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Sep 2008 15:19:28 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2008-09-16T15:19:28Z</dc:date>
    <item>
      <title>Help with PIX configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096600#M896326</link>
      <description>&lt;P&gt;I need to open ports on the firewall for the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port 80 From IP - 172.16.1.20 (in DMZ) to 195.118.216.163 (internal&lt;/P&gt;&lt;P&gt;network)&lt;/P&gt;&lt;P&gt;Port 1433 From IP 172.16.1.20 (in DMZ) to 195.118.216.163 (Internal&lt;/P&gt;&lt;P&gt;Network)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also need to label the ports ie: 1433 SQL and HTTP 80 and specify a name for the rule ie: "Gateway to Swordfish Claims communication" if possible so we can keep track of the rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do do I configure this on a PIX firewall&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096600#M896326</guid>
      <dc:creator>patel.nishit</dc:creator>
      <dc:date>2019-03-11T13:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Help with PIX configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096601#M896328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list dmz2internal extended permit tcp host 172.16.1.20 host 195.1189.216.163 eq 80&lt;/P&gt;&lt;P&gt;access-list dmz2internal extended permit tcp host 172.16.1.20 host 195.1189.216.163 eq 1433&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port 80 will be renamed (in the config) to HTTP and 1422 to SQLNET. I don't think there is a way to change them. For marking what an ACL does, you can add a remark.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz2internal extended remark Gateway to Swordfish Claims communication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2008 15:13:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096601#M896328</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-09-16T15:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Help with PIX configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096602#M896331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You configure this in fw.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try something like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create no nat static entry&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,DMZ) 195.118.216.163 195.118.216.163 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create object group for tcp with description&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service TCP_GW_SWORFISH tcp&lt;/P&gt;&lt;P&gt;description Gateway to Sorfish&lt;/P&gt;&lt;P&gt;port-object eq 1433&lt;/P&gt;&lt;P&gt;port-object eq 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then acl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark gateway_to_sorfish&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit tcp host 172.16.1.20  host 195.118.216.163 object-group TCP_GW_SWORFISH&lt;/P&gt;&lt;P&gt;access-group DMZ_access_in in interface DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2008 15:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096602#M896331</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-09-16T15:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Help with PIX configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096603#M896333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do I need to create an object group for this on pix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2008 15:17:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096603#M896333</guid>
      <dc:creator>patel.nishit</dc:creator>
      <dc:date>2008-09-16T15:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Help with PIX configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096604#M896335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Either way will work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2008 15:19:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096604#M896335</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-09-16T15:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Help with PIX configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096605#M896338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you do not have to create object group, it is a matter of  preference, I like to have object groups segregated so I group them as such so that I know who I use the group for, fruthermore creating groups is easy as you can add more tcp services to them as support to individual acls per tcp udp ports.. and I do agree with Collin as well..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2008 15:21:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096605#M896338</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-09-16T15:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help with PIX configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096606#M896342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I try to enter this acl it is giving me error invalid hostname.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz2internal extended remark Gateway to Swordfish Claims communication&lt;/P&gt;&lt;P&gt;access-list dmz2internal extended permit tcp host 172.16.1.20 host 195.1189.216.163 eq 80&lt;/P&gt;&lt;P&gt;access-list dmz2internal extended permit tcp host 172.16.1.20 host 195.1189.216.163 eq 1433&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2008 15:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096606#M896342</guid>
      <dc:creator>patel.nishit</dc:creator>
      <dc:date>2008-09-16T15:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Help with PIX configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096607#M896347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Second octet in the second IP, 1189 won't work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2008 15:29:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096607#M896347</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-09-16T15:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Help with PIX configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096608#M896349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it worked thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2008 07:14:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-configuration/m-p/1096608#M896349</guid>
      <dc:creator>patel.nishit</dc:creator>
      <dc:date>2008-09-17T07:14:09Z</dc:date>
    </item>
  </channel>
</rss>

