11-14-2001 07:08 AM - edited 02-20-2020 09:54 PM
I have two new 515 boxes that I upgraded from an old 520. I have kept some of the config, including this established command below.
established tcp 135 0 permitto tcp 1024-65535 permitfrom tcp 0
This was put in the pix config before I joined the company and no-one seems to know its purpose! I am worried about taking it out incase i break something! Digging around the cisco site I have found that it may be something to do with our exchange server. Anyway, I am running version 6 Pix and cannot get the PDM working because it doesnt like this command! Anyone help?
11-15-2001 09:08 AM
This probably was used for the communication from the Exchange Server. There is a certain amount of risk when you allow any host that is connected on port 135 to make a new connection on some unknown high port. Check out this link from Microsoft that explains the communication for Exchange. It will help you to nail down and isolate the ports required for this communication, depending on your implementation of Exchange Server.
http://support.microsoft.com/support/kb/articles/Q176/4/66.ASP
Hope this helps...
Marcus
11-15-2001 10:10 AM
Try the steps out lined here
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v51/config/msexchng.htm
11-22-2001 01:05 AM
that is a very interesting article but I think the point of my problem was missed! The Pix is configured for use with the Exchange Server, and has the established command statement to allow back connections. However, my problem is with the PDM. When I try to load the PDM (v1.0.2), I get errors that point to the PDM not supporting this established command. The message I get when starting up PDM is below:
PDM does not support the established command in your configuration. Use the CLI to fix the unsupported command and then refresh PDM with the modified PIX Configuration.
Has anyone else seen this error message when running PDM?
11-23-2001 05:28 AM
I wouldn't have thought the PDM software, would understand "established" command since it is pretty advanced feature, just like the PDM doesn't currently understand / support VPN configuration information.
Regards,
Regan
11-23-2001 01:56 PM
if the established command only used to support your
exchange server, you can reconfigure the exchange server to use static ports (ms kb id Q270836 and Q148732), after this change your access-lists to permit these connections. at this point you can remove the established command.
Best regards
Thomas
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide