cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
381
Views
0
Helpful
2
Replies

PIX 501 http acces from outside to inside server

Kvolsgaard
Level 1
Level 1

Hey

I have a PIX 501 and i want to be abel to acces my webserver(172.16.17.4) from outside on port 80. How do i do that??

My config looks like this now. No matter what i try it doesn't work.

I have 1 public IP-Address.

Building configuration...

: Saved

:

PIX Version 6.3(4)

interface ethernet0 auto

interface ethernet1 100full

nameif ethernet0 outside security0

nameif ethernet1 inside security100

enable password ****** encrypted

passwd ***** encrypted

hostname pix

domain-name ???.dk

fixup protocol dns maximum-length 512

fixup protocol ftp 21

fixup protocol h323 h225 1720

fixup protocol h323 ras 1718-1719

fixup protocol http 80

fixup protocol rsh 514

fixup protocol rtsp 554

fixup protocol sip 5060

fixup protocol sip udp 5060

fixup protocol skinny 2000

fixup protocol smtp 25

fixup protocol sqlnet 1521

fixup protocol tftp 69

names

pager lines 24

mtu outside 1500

mtu inside 1500

ip address outside x.x.x.62 255.255.255.252

ip address inside 172.16.17.1 255.255.255.0

ip audit info action alarm

ip audit attack action alarm

pdm logging informational 100

pdm history enable

arp timeout 14400

global (outside) 1 interface

nat (inside) 1 0.0.0.0 0.0.0.0 0 0

route outside 0.0.0.0 0.0.0.0 x.x.x.61 1

timeout xlate 0:05:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00

timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00

timeout uauth 0:05:00 absolute

aaa-server TACACS+ protocol tacacs+

aaa-server TACACS+ max-failed-attempts 3

aaa-server TACACS+ deadtime 10

aaa-server RADIUS protocol radius

aaa-server RADIUS max-failed-attempts 3

aaa-server RADIUS deadtime 10

aaa-server LOCAL protocol local

http server enable

http 172.16.17.0 255.255.255.0 inside

no snmp-server location

no snmp-server contact

snmp-server community public

no snmp-server enable traps

floodguard enable

telnet timeout 5

ssh timeout 5

console timeout 0

dhcpd address 172.16.17.100-172.16.17.200 inside

dhcpd dns 194.239.134.83 193.162.153.164

dhcpd lease 86400

dhcpd ping_timeout 750

dhcpd domain 3po.dk

dhcpd auto_config outside

dhcpd enable inside

terminal width 80

Cryptochecksum:xxxx

: end

[OK]

2 Replies 2

rais.ahmad
Level 1
Level 1

You need this statement:

static (inside, outside) tcp 80 172.16.17.4 80 netmask 255.255.255.255

You also need access-list to allow access to port 80:

access-list listname permit tcp any host 172.16.17.4 80

Hope this helps.

stalljh
Level 1
Level 1

From the outside, you need to set up a static translation so that you web server has a virtual IP out in the cloud. Then you allow that IP through the outside interface of the PIX with an access-list to the web server ip. You need to use a public address to translate to. So if you only have one public address and you are using that on the outside interface of the PIX, then you need to get another address from the ISP if you want to get into your web from the outside.

Review Cisco Networking for a $25 gift card