<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX515, TCP static mapping but no ICMP? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix515-tcp-static-mapping-but-no-icmp/m-p/795955#M977493</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That won't work, because port 8080 on the actual server needs to be translated as port 80 on the external address.&lt;/P&gt;&lt;P&gt;There are multiple servers in that environment, all of them accessible from the outside over port 80, which is translated by the firewall as port 8080 on the actual machines.&lt;/P&gt;&lt;P&gt;Each server has its own public address on the outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Jun 2007 20:19:25 GMT</pubDate>
    <dc:creator>hws_admin</dc:creator>
    <dc:date>2007-06-27T20:19:25Z</dc:date>
    <item>
      <title>PIX515, TCP static mapping but no ICMP?</title>
      <link>https://community.cisco.com/t5/network-security/pix515-tcp-static-mapping-but-no-icmp/m-p/795953#M977491</link>
      <description>&lt;P&gt;I've a PIX-515 firewall, running 7.2.2, in front of a private network. Servers in the private network are statically mapped to the external interface like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp host-outside www host-inside 8080 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is, now ICMP is not translated anymore. If I try to ping host-outside from the Internet, the firewall says "Deny inbound icmp src outside" even though ICMP is allowed by the ACL to all destinations on the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to add something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) host-outside host-inside netmask .......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But then the firewall tells me there's a conflict between this more general mapping, and the existing more specific mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I keep the TCP 80 -&amp;gt; 8080 mapping but also translate inbound ICMP requests?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:36:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515-tcp-static-mapping-but-no-icmp/m-p/795953#M977491</guid>
      <dc:creator>hws_admin</dc:creator>
      <dc:date>2019-03-11T10:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: PIX515, TCP static mapping but no ICMP?</title>
      <link>https://community.cisco.com/t5/network-security/pix515-tcp-static-mapping-but-no-icmp/m-p/795954#M977492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would have to remove all port translations and add a 1 to 1 static. That may or may not work for you as you may have other inside servers using this outside address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no static (inside,outside) tcp host-outside www host-inside 8080 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) host-outside host-inside netmask ....... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2007 19:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515-tcp-static-mapping-but-no-icmp/m-p/795954#M977492</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-27T19:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX515, TCP static mapping but no ICMP?</title>
      <link>https://community.cisco.com/t5/network-security/pix515-tcp-static-mapping-but-no-icmp/m-p/795955#M977493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That won't work, because port 8080 on the actual server needs to be translated as port 80 on the external address.&lt;/P&gt;&lt;P&gt;There are multiple servers in that environment, all of them accessible from the outside over port 80, which is translated by the firewall as port 8080 on the actual machines.&lt;/P&gt;&lt;P&gt;Each server has its own public address on the outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2007 20:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515-tcp-static-mapping-but-no-icmp/m-p/795955#M977493</guid>
      <dc:creator>hws_admin</dc:creator>
      <dc:date>2007-06-27T20:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: PIX515, TCP static mapping but no ICMP?</title>
      <link>https://community.cisco.com/t5/network-security/pix515-tcp-static-mapping-but-no-icmp/m-p/795956#M977494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which is why I said "That may or may not work for you as you may have other inside servers using this outside address."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2007 21:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515-tcp-static-mapping-but-no-icmp/m-p/795956#M977494</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-27T21:16:16Z</dc:date>
    </item>
  </channel>
</rss>

