<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACL help on PIX 506E in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873526#M958995</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I have a PIX 506e v6.3. I need to provide outside access to port 80 and port 3389 on one inside client and access to port 1433 on another client. I've come up with access lists something like this: (12.12.12.12 is the outside interface on the pix and 24.24.24.24 is a remote location I want to have access)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 110 permit tcp host 192.168.99.95 host 12.12.12.12 eq www&lt;/P&gt;&lt;P&gt;access-list 110 permit tcp host 192.168.99.94 host 12.12.12.12 eq 1433&lt;/P&gt;&lt;P&gt;access-list 110 permit tcp host 192.168.99.95 host 24.24.24.24 eq 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group 110 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 12.12.12.12 192.168.99.95 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) 12.12.12.12 192.168.99.94 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:41:55 GMT</pubDate>
    <dc:creator>ed-rucker</dc:creator>
    <dc:date>2019-03-11T11:41:55Z</dc:date>
    <item>
      <title>ACL help on PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873526#M958995</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I have a PIX 506e v6.3. I need to provide outside access to port 80 and port 3389 on one inside client and access to port 1433 on another client. I've come up with access lists something like this: (12.12.12.12 is the outside interface on the pix and 24.24.24.24 is a remote location I want to have access)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 110 permit tcp host 192.168.99.95 host 12.12.12.12 eq www&lt;/P&gt;&lt;P&gt;access-list 110 permit tcp host 192.168.99.94 host 12.12.12.12 eq 1433&lt;/P&gt;&lt;P&gt;access-list 110 permit tcp host 192.168.99.95 host 24.24.24.24 eq 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group 110 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 12.12.12.12 192.168.99.95 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) 12.12.12.12 192.168.99.94 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:41:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873526#M958995</guid>
      <dc:creator>ed-rucker</dc:creator>
      <dc:date>2019-03-11T11:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: ACL help on PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873527#M958996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you want a remote location (24.24.24.24) to access your inside client (12.12.12.12)?&lt;/P&gt;&lt;P&gt;If you want to access remote location (24.24.24.24) from inside client (12.12.12.12) you dont need ACLs, if your default config is not flitered with inside_access_in&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 09:58:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873527#M958996</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-11T09:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACL help on PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873528#M958998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;12.12.12.12 is the outside interface on the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 10:31:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873528#M958998</guid>
      <dc:creator>ed-rucker</dc:creator>
      <dc:date>2007-12-11T10:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: ACL help on PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873529#M958999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would you please rephrase your situation by using "from" and "to"&lt;/P&gt;&lt;P&gt;btw you cant one-to-one map 1 IP to two hosts&lt;/P&gt;&lt;P&gt;static (inside,outside) 12.12.12.12 192.168.99.95 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) 12.12.12.12 192.168.99.94 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;And you cant map interface IP like that. I will start posting as I correctly understand the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 11:05:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873529#M958999</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-11T11:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACL help on PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873530#M959002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to go from outside any to inside 192.168.99.95 eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to go from outside any to inside 192.168.99.94 eq 1433&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and last from outside 24.24.24.24 to inside 192.168.99.95 eq 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 11:14:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873530#M959002</guid>
      <dc:creator>ed-rucker</dc:creator>
      <dc:date>2007-12-11T11:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACL help on PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873531#M959004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ed&lt;/P&gt;&lt;P&gt;Here is what you need&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface www 192.168.99.95 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 3389 192.168.99.95 3389 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 1433 192.168.99.94 1433 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any interface outside eq www&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any interface outside eq 1433&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp host 24.24.24.24 interface outside eq 3389&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 12:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873531#M959004</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-11T12:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: ACL help on PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873532#M959007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You, Thank You, Thank You, You are most Excelante'!  -  Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 14:03:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873532#M959007</guid>
      <dc:creator>ed-rucker</dc:creator>
      <dc:date>2007-12-11T14:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: ACL help on PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873533#M959009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are welcome&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 14:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-help-on-pix-506e/m-p/873533#M959009</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-11T14:06:29Z</dc:date>
    </item>
  </channel>
</rss>

