<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX506E basic config in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813667#M969902</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to Firewalls and I have to configure a 506E between the production (Enterpise) network and a new test lab.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;This is to ensure that any activities within the test area do not interfere with any operations on the production network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both the test lab and the production network are using private address ranges.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume I do not need to use NAT as neither address range needs to be 'hidden' from the other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have put the inside (secure) network towards the lab and insecure towards production network (just in case we need to VPN to outside interface across production network in the future).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We only want to allow HTTP and telnet through (in both directions, ie inside to outside and vice versa).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you have an example configuration I could use to get started?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in anticipation to somebody helping me out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:07:49 GMT</pubDate>
    <dc:creator>mark-bear</dc:creator>
    <dc:date>2019-03-11T11:07:49Z</dc:date>
    <item>
      <title>PIX506E basic config</title>
      <link>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813667#M969902</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to Firewalls and I have to configure a 506E between the production (Enterpise) network and a new test lab.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;This is to ensure that any activities within the test area do not interfere with any operations on the production network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both the test lab and the production network are using private address ranges.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume I do not need to use NAT as neither address range needs to be 'hidden' from the other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have put the inside (secure) network towards the lab and insecure towards production network (just in case we need to VPN to outside interface across production network in the future).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We only want to allow HTTP and telnet through (in both directions, ie inside to outside and vice versa).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you have an example configuration I could use to get started?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in anticipation to somebody helping me out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813667#M969902</guid>
      <dc:creator>mark-bear</dc:creator>
      <dc:date>2019-03-11T11:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: PIX506E basic config</title>
      <link>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813668#M969903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to configure access-lists to allow only telnet and http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sample:&lt;/P&gt;&lt;P&gt;access-list 101 tcp permit any any eq 80&lt;/P&gt;&lt;P&gt;access-list 101 tcp permit any any eq 23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group 101 out interface &lt;INSIDE_INTERFACE name=""&gt;&lt;/INSIDE_INTERFACE&gt;&lt;/P&gt;&lt;P&gt;access-group 101 in interface &lt;OUTSIDE_INTERFACE name=""&gt;&lt;/OUTSIDE_INTERFACE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 05:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813668#M969903</guid>
      <dc:creator>rajinikanth</dc:creator>
      <dc:date>2007-09-07T05:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX506E basic config</title>
      <link>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813669#M969904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assume test network is 192.168.5.0/24 &lt;/P&gt;&lt;P&gt;Assume production network is 172.16.5.0/24 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate you may have bigger network ranges so you can adjust access-list accordingly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_out permit tcp 192.168.5.0 255.255.255.0 172.16.5.0 255.255.255.0 eq http&lt;/P&gt;&lt;P&gt;access-list inside_out permit tcp 192.168.5.0 255.255.255.0 172.16.5.0 255.255.255.0 eq telnet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inside_out in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp 172.16.5.0 255.255.255.0 192.168.5.0 255.255.255.0 eq http&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp 172.16.5.0 255.255.255.0 192.168.5.0 255.255.255.0 eq telnet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.5.0 192.168.5.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple of things&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) if you are happy to have the addressing mix then no you do not need to do NAT (although you still need the static statement above ). What we do is present lab addresses as prodcution address to the production users and then we NAT them back to the real address on the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) I appreciate your point about VPN but your firewall is really the wrong way round in my opinion. You should have the inside interface facing the network you want to secure and i'm assuming your production environment is more important than your test lab ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do what you have done but just be aware that by default traffic can flow from higher to lower level security interface so you need to be very precise with the access-list on your inside interface which effectively says what traffic is allowed from the test lab to production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 05:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813669#M969904</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-07T05:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: PIX506E basic config</title>
      <link>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813670#M969905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for responding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My main issue is configuring any translations or do I not need to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both the inside network and the outside network are using different 10 private address ranges.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you think?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 05:52:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813670#M969905</guid>
      <dc:creator>mark-bear</dc:creator>
      <dc:date>2007-09-07T05:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX506E basic config</title>
      <link>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813671#M969907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for comprehensive response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should the static statement you mentioned read:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 172.16.5.0 192.168.5.0 netmask 255.255.255.0  ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just two more questions if I may, both sides of the firewall are using 10 network address ranges for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP range for lab is:&lt;/P&gt;&lt;P&gt;10.10.240.0/20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP range for production network is:&lt;/P&gt;&lt;P&gt;all other 10 addresses ranges&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this be a problem as far as the Firewall is concerned?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Final question, you mentioned in your point 1 dont need to NAT etc, then you go on to say "then we NAT them back to the real address on the firewall". So I'm a little confused now on this point. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Thanks for responding again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mark&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 09:09:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813671#M969907</guid>
      <dc:creator>mark-bear</dc:creator>
      <dc:date>2007-09-07T09:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: PIX506E basic config</title>
      <link>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813672#M969909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To cover off the static / NAT issues first. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To allow connections from a lower to higher security interface you need to have static &lt;/P&gt;&lt;P&gt;translations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.5.0 192.168.5.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;means present the 192.168.5.x network addresses to the outside (in our case production) &lt;/P&gt;&lt;P&gt;as 192.168.5.x addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is a peculiarity of the pix that even if you don't want to NAT from one IP address to &lt;/P&gt;&lt;P&gt;another you still need to tell the pix that you don't want to NAT and this is what the&lt;/P&gt;&lt;P&gt;static statement does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Note with Pix v7.x code this has changed quite significantly but your pix will be running &lt;/P&gt;&lt;P&gt;6.3 code as it is a pix 506e which can't run v7.x)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i mentioned the bit about is natting them back on the firewall i was talking about&lt;/P&gt;&lt;P&gt;what we do in our environment but as i say if it's not a problem mixing your addressing&lt;/P&gt;&lt;P&gt;then don't worry about this. As long as none of your prod/test addressing overlaps you &lt;/P&gt;&lt;P&gt;should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 10:01:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813672#M969909</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-07T10:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: PIX506E basic config</title>
      <link>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813673#M969911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have been really helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 11:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix506e-basic-config/m-p/813673#M969911</guid>
      <dc:creator>mark-bear</dc:creator>
      <dc:date>2007-09-07T11:27:59Z</dc:date>
    </item>
  </channel>
</rss>

