<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS thru a PIX on non-standard port in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/https-thru-a-pix-on-non-standard-port/m-p/829679#M956244</link>
    <description>&lt;P&gt;We have SSL running on a non standard port that must traverse a PIX.  &lt;/P&gt;&lt;P&gt;It's a 525 running 8.0.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i attempt to use a browser to access the site:  &lt;A class="jive-link-custom" href="https://x.x.10.51:8021" target="_blank"&gt;https://x.x.10.51:8021&lt;/A&gt;  i get timed out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i attempt to telnet x.x.10.51 8021 i get a successful connection.  &lt;/P&gt;&lt;P&gt;rcirs001:/&amp;gt;telnet x.x.10.51 8021&lt;/P&gt;&lt;P&gt;Trying...&lt;/P&gt;&lt;P&gt;Connected to x.x.10.51.&lt;/P&gt;&lt;P&gt;Escape character is '^]'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i capture or sho conn det i get the same thing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the browser:&lt;/P&gt;&lt;P&gt;MDCWSPDEVPIX01# sho capture capout &lt;/P&gt;&lt;P&gt;0 packet captured&lt;/P&gt;&lt;P&gt;0 packet shown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From command line:&lt;/P&gt;&lt;P&gt;MDCWSPDEVPIX01# sho capture capout&lt;/P&gt;&lt;P&gt;2 packets captured&lt;/P&gt;&lt;P&gt;   1: 10:47:42.085658 mysource.42361 &amp;gt; x.x.10.51.8021: S 1424688632:1424688632(0) win 16384 &amp;lt;mss 1380&amp;gt;&lt;/P&gt;&lt;P&gt;   2: 10:47:42.096644 mysource.42361 &amp;gt; x.x.10.51.8021: . ack 589207218 win 1656&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AND&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the browser:&lt;/P&gt;&lt;P&gt;sho conn detail | i x.x.10.51&lt;/P&gt;&lt;P&gt;nothing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the command line:&lt;/P&gt;&lt;P&gt;sho conn detail | i x.x.10.51&lt;/P&gt;&lt;P&gt;TCP outside:mysource/39094 inside:x.x.10.51/8021 flags UB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i understand telnetting to this port doesn't verify the server - i'm just trying to illustrate that there's an issue in how a PIX sees the HTTP protocol over a non standard port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the past for other protocols i would have used fixup or inspect for the non-standard ports...  but i see no SSL support there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;-=Chris&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:54:28 GMT</pubDate>
    <dc:creator>cramman</dc:creator>
    <dc:date>2019-03-11T11:54:28Z</dc:date>
    <item>
      <title>HTTPS thru a PIX on non-standard port</title>
      <link>https://community.cisco.com/t5/network-security/https-thru-a-pix-on-non-standard-port/m-p/829679#M956244</link>
      <description>&lt;P&gt;We have SSL running on a non standard port that must traverse a PIX.  &lt;/P&gt;&lt;P&gt;It's a 525 running 8.0.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i attempt to use a browser to access the site:  &lt;A class="jive-link-custom" href="https://x.x.10.51:8021" target="_blank"&gt;https://x.x.10.51:8021&lt;/A&gt;  i get timed out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i attempt to telnet x.x.10.51 8021 i get a successful connection.  &lt;/P&gt;&lt;P&gt;rcirs001:/&amp;gt;telnet x.x.10.51 8021&lt;/P&gt;&lt;P&gt;Trying...&lt;/P&gt;&lt;P&gt;Connected to x.x.10.51.&lt;/P&gt;&lt;P&gt;Escape character is '^]'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i capture or sho conn det i get the same thing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the browser:&lt;/P&gt;&lt;P&gt;MDCWSPDEVPIX01# sho capture capout &lt;/P&gt;&lt;P&gt;0 packet captured&lt;/P&gt;&lt;P&gt;0 packet shown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From command line:&lt;/P&gt;&lt;P&gt;MDCWSPDEVPIX01# sho capture capout&lt;/P&gt;&lt;P&gt;2 packets captured&lt;/P&gt;&lt;P&gt;   1: 10:47:42.085658 mysource.42361 &amp;gt; x.x.10.51.8021: S 1424688632:1424688632(0) win 16384 &amp;lt;mss 1380&amp;gt;&lt;/P&gt;&lt;P&gt;   2: 10:47:42.096644 mysource.42361 &amp;gt; x.x.10.51.8021: . ack 589207218 win 1656&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AND&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the browser:&lt;/P&gt;&lt;P&gt;sho conn detail | i x.x.10.51&lt;/P&gt;&lt;P&gt;nothing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the command line:&lt;/P&gt;&lt;P&gt;sho conn detail | i x.x.10.51&lt;/P&gt;&lt;P&gt;TCP outside:mysource/39094 inside:x.x.10.51/8021 flags UB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i understand telnetting to this port doesn't verify the server - i'm just trying to illustrate that there's an issue in how a PIX sees the HTTP protocol over a non standard port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the past for other protocols i would have used fixup or inspect for the non-standard ports...  but i see no SSL support there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;-=Chris&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-thru-a-pix-on-non-standard-port/m-p/829679#M956244</guid>
      <dc:creator>cramman</dc:creator>
      <dc:date>2019-03-11T11:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS thru a PIX on non-standard port</title>
      <link>https://community.cisco.com/t5/network-security/https-thru-a-pix-on-non-standard-port/m-p/829680#M956245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like your workstation is not even getting to your pix when you go to that weblink.  Are you using a proxy server?  Is there a router behind the pix that may be blocking that port?  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2008 19:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-thru-a-pix-on-non-standard-port/m-p/829680#M956245</guid>
      <dc:creator>robert.horrigan</dc:creator>
      <dc:date>2008-01-31T19:33:57Z</dc:date>
    </item>
  </channel>
</rss>

