<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco PIX 501 problems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794085#M975593</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;BTW port 2086 it's already in access-list outside_acces_in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 2086 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Aug 2007 23:32:00 GMT</pubDate>
    <dc:creator>me19562</dc:creator>
    <dc:date>2007-08-16T23:32:00Z</dc:date>
    <item>
      <title>Cisco PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794081#M975587</link>
      <description>&lt;P&gt;I`m a very new to cisco management, so here are my issues. &lt;/P&gt;&lt;P&gt;1. I`ve been trying to open port 2086 inbound and outbound and I don`t know how to do it.&lt;/P&gt;&lt;P&gt;2. For some reason the firewall is not letting smpt connect outside.&lt;/P&gt;&lt;P&gt;Here is my firewall configuration :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;hostname pixfirewall&lt;/P&gt;&lt;P&gt;domain-name linux.secureserver.net&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq ftp-data &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq ftp &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq ssh &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 42 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit udp any any eq nameserver &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq domain &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit udp any any eq domain &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq pop3 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 465 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 587 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 995 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 993 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 3389 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 8443 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 9999 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 2086 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 2087 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 2082 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 2083 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 2096 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 2095 &lt;/P&gt;&lt;P&gt;access-list outside_access_in deny tcp any any eq telnet &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:58:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794081#M975587</guid>
      <dc:creator>bin_asc_adrian</dc:creator>
      <dc:date>2019-03-11T10:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794082#M975588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list outside_access_in deny tcp any any eq imap4 &lt;/P&gt;&lt;P&gt;access-list outside_access_in deny tcp any any eq 1433 &lt;/P&gt;&lt;P&gt;access-list outside_access_in deny tcp any any eq 3306 &lt;/P&gt;&lt;P&gt;access-list outside_access_in deny tcp any any eq 9080 &lt;/P&gt;&lt;P&gt;access-list outside_access_in deny tcp any any eq 9090 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any source-quench &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 7080 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 2080 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 55555 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 125 &lt;/P&gt;&lt;P&gt;access-list in_access_outside permit tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list smtp permit tcp any host outsideip1 eq smtp &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside cisco.pix.ip 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 10.0.0.254 255.255.255.0&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm location 10.0.0.1 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm location outside.ip1 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 10.0.0.1 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 10.0.0.2 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm location outside.ip2 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location my.home.ip 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;static (outside,inside) 10.0.0.1 outside.ip1 dns netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) outside.ip1 10.0.0.1 dns netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (outside,inside) 10.0.0.2 outside.ip2 dns netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) outside.ip2 10.0.0.2 dns netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;access-group smtp in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 208.109.90.254 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3 &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10 &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3 &lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10 &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;http 10.0.0.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;management-access outside&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please guide me through to fixing these issues. I also don`t know how to connect to the pix ssh...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2007 21:29:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794082#M975588</guid>
      <dc:creator>bin_asc_adrian</dc:creator>
      <dc:date>2007-08-16T21:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794083#M975589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, right now after looking at your config you are nousing any of the access-list outside_access_in. The only acl apply right now is access-list smtp and it's apply to the outside interface. If what you want it's allow traffic to port 25 in host outsideip1 from anywhere, then modify the acl that already exist&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq smtp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host outsideip1 eq smtp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then apply the ACL's outside_access_in to the ouside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the NAT, you should be good with only these static entries unless you are trying to do something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) outside.ip1 10.0.0.1 dns netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) outside.ip2 10.0.0.2 dns netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2007 22:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794083#M975589</guid>
      <dc:creator>me19562</dc:creator>
      <dc:date>2007-08-16T22:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794084#M975590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 2084&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dharmesh Purohit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2007 23:23:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794084#M975590</guid>
      <dc:creator>purohit_810</dc:creator>
      <dc:date>2007-08-16T23:23:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 501 problems</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794085#M975593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;BTW port 2086 it's already in access-list outside_acces_in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any any eq 2086 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2007 23:32:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problems/m-p/794085#M975593</guid>
      <dc:creator>me19562</dc:creator>
      <dc:date>2007-08-16T23:32:00Z</dc:date>
    </item>
  </channel>
</rss>

