<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tivo access through PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851102#M957982</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Christopher&lt;/P&gt;&lt;P&gt;  I am assuming Tivo01 is not in outside interface so you cannot write ACLs as above. Also no translations (Static etc) exists&lt;/P&gt;&lt;P&gt;  Is public IP going to be conneted for reaching Tivo01? Is Tivo01 in inside interface? Do you have another public IP then interface IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Dec 2007 21:40:49 GMT</pubDate>
    <dc:creator>Alan Huseyin Kayahan</dc:creator>
    <dc:date>2007-12-27T21:40:49Z</dc:date>
    <item>
      <title>Tivo access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851101#M957981</link>
      <description>&lt;P&gt;I got a Tivo for Christmas and I'm trying to open the appropriate ports on my PIX 501 to allow it to communicate with the Tivo service.  The Tivo knowlege base says I need to open these ports for inbound and outboud access:&lt;/P&gt;&lt;P&gt;  - TCP 37,2190,4430, 7287-7288, 8000, 8080-8090&lt;/P&gt;&lt;P&gt;  - UDP 123, 2190&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to set up an access list that only allows access over these ports to my Tivo box (internal IP 192.168.1.11) and prohibits access to other hosts on my inside interface over those same ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to set up an access-list using the following config commands, but it's not working.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 192.168.1.2 Neptune&lt;/P&gt;&lt;P&gt;name 192.168.1.11 Tivo01&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 37&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 2190&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 4430&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 range 7287 7288&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 8000&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 range 8080 8089&lt;/P&gt;&lt;P&gt;access-list acl-in permit udp any host Tivo01 eq ntp&lt;/P&gt;&lt;P&gt;access-list acl-in permit udp any host Tivo01 eq 2190&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;access-group acl-in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 69.73.72.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A debug trace when I attempt to connect from the tivo box to the tivo service includes the following suspicious entry:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;710005: UDP request discarded from 192.168.1.11/2190 to inside:192.168.1.255/2190&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts on what's going on?  A missing routing entry perhaps?? It almost looks like the Tivo's UDP request is getting broadcast to hosts on my internal LAN, but not getting routed outside?? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW: Normal web traffic (inside clients hitting external web servers) works with no problems.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:55:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851101#M957981</guid>
      <dc:creator>christopherfrancis</dc:creator>
      <dc:date>2019-03-13T00:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Tivo access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851102#M957982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Christopher&lt;/P&gt;&lt;P&gt;  I am assuming Tivo01 is not in outside interface so you cannot write ACLs as above. Also no translations (Static etc) exists&lt;/P&gt;&lt;P&gt;  Is public IP going to be conneted for reaching Tivo01? Is Tivo01 in inside interface? Do you have another public IP then interface IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Dec 2007 21:40:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851102#M957982</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-27T21:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Tivo access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851103#M957983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Tivo is on the Inside interface (192.168.1.x subnet).  The Tivo's IP is 192.168.1.11.  The PIX has a public external IP of 69.73.xx.xx.  It's internal (gateway) address is 192.168.1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was expecting that the PIX would route outgoing requests from the Tivo to it's outside interface, but it appears to be dropping them.  Not sure why.  Similarly, I had expected the PIX to translaste/route responses from the Tivo server on the outside network to the correct internal (NAT'd) IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect I've got a routing issue, but I'm not sure what I need to do to solve it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Dec 2007 22:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851103#M957983</guid>
      <dc:creator>christopherfrancis</dc:creator>
      <dc:date>2007-12-27T22:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: Tivo access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851104#M957984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do this and it will work for you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;2- global (outside) 1 interface&lt;/P&gt;&lt;P&gt;3- access-list test permit ip any any log&lt;/P&gt;&lt;P&gt;4- access-group test in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;step 3 &amp;amp; 4 is optional but I put them in &lt;/P&gt;&lt;P&gt;there for testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2007 03:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851104#M957984</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2007-12-28T03:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Tivo access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851105#M957985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;forget to add another step:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5- access-group test in interface outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this will make sure your firewall is &lt;/P&gt;&lt;P&gt;wide-open.  Once you get it working, start&lt;/P&gt;&lt;P&gt;locking down the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2007 03:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851105#M957985</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2007-12-28T03:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Tivo access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851106#M957986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sure it will work if I open everything up.  What I'm trying to do is figure out how to make it work without doing that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I've narrowed it down to an issue with ICMP.  Apparently the Tivo box tries to Ping the Tivo server to verify connectivity before launching into the rest of its "conversation".  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I'm now trying to set up the PIX to allow the Tivo to Ping through the firewall, but am still running into problems.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what my access list looks like now:&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 37&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 2190&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 4430&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 range 7287 7288&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 8000&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 range 8080 8089&lt;/P&gt;&lt;P&gt;access-list acl-in permit udp any host Tivo01 eq ntp&lt;/P&gt;&lt;P&gt;access-list acl-in permit udp any host Tivo01 eq 2190&lt;/P&gt;&lt;P&gt;access-list acl-in permit icmp any host Tivo01 echo&lt;/P&gt;&lt;P&gt;access-list acl-in permit icmp any host Tivo01 echo-reply&lt;/P&gt;&lt;P&gt;access-group acl-in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Dec 2007 23:08:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851106#M957986</guid>
      <dc:creator>christopherfrancis</dc:creator>
      <dc:date>2007-12-30T23:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Tivo access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851107#M957987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging buffer-size 1048576&lt;/P&gt;&lt;P&gt;logging buffered informational&lt;/P&gt;&lt;P&gt;logging trap informational&lt;/P&gt;&lt;P&gt;logging mail informational&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 37 log&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 2190 log&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 4430 log&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 range 7287 7288 log&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 eq 8000 log&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any host Tivo01 range 8080 8089 log&lt;/P&gt;&lt;P&gt;access-list acl-in permit udp any host Tivo01 eq ntp log&lt;/P&gt;&lt;P&gt;access-list acl-in permit udp any host Tivo01 eq 2190 log&lt;/P&gt;&lt;P&gt;access-list acl-in permit icmp any host Tivo01 echo log&lt;/P&gt;&lt;P&gt;access-list acl-in permit icmp any host Tivo01 echo-reply log&lt;/P&gt;&lt;P&gt;access-list acl-in deny ip any any log&lt;/P&gt;&lt;P&gt;access-group acl-in in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that, on the Pix, do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CiscoPix# sh log | i Deny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will tell you what is being dennied&lt;/P&gt;&lt;P&gt;on the outside interface.  You will then&lt;/P&gt;&lt;P&gt;have to open additional port(s) for it to &lt;/P&gt;&lt;P&gt;work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would start from there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCIE Security&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Dec 2007 01:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851107#M957987</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2007-12-31T01:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Tivo access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851108#M957988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David,&lt;/P&gt;&lt;P&gt;  Above ACLs have no use for allowing inbound connections. Tivo01 is a host in inside interface not outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Christopher,&lt;/P&gt;&lt;P&gt;  For allowing outbound connection from Tivo, you need the following ACE in ACL which is grouped to your inside interface (if exists)&lt;/P&gt;&lt;P&gt;  First, chek if you have an ACL grouped to inside interface&lt;/P&gt;&lt;P&gt;sh run access-group&lt;/P&gt;&lt;P&gt;  If you see an xxxx (considering xxxx as your acl name if exists) as following&lt;/P&gt;&lt;P&gt;access-group xxxx in interface inside&lt;/P&gt;&lt;P&gt;  then you need to add following&lt;/P&gt;&lt;P&gt;access-list xxxx permit tcp Tivo01 eq 37 any&lt;/P&gt;&lt;P&gt;access-list xxxx permit tcp Tivo01 eq 2190 any&lt;/P&gt;&lt;P&gt;  Same for your other ports&lt;/P&gt;&lt;P&gt;  And for inbound connection, which should be established to your outside interface in this case, you should first create statics as following&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 37 Tivo01 37 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 2190 Tivo01 2190 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;   Same for other ports. (I suggest a dedicated public IP instead interface IP)&lt;/P&gt;&lt;P&gt;   Then, allow the port traffic to interface as&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any interface outside eq 37&lt;/P&gt;&lt;P&gt;access-list acl-in permit tcp any interface outside eq 2190&lt;/P&gt;&lt;P&gt;   Same for other ports. &lt;/P&gt;&lt;P&gt;   Keep in mind that, you dont have to allow inbound connection from a host in public, if the session is started from a host in your inside network.&lt;/P&gt;&lt;P&gt;   If you still have problems, please post me your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Dec 2007 08:44:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tivo-access-through-pix/m-p/851108#M957988</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-31T08:44:00Z</dc:date>
    </item>
  </channel>
</rss>

