cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1035
Views
0
Helpful
2
Replies

PIX RAS Config

rtivnan
Level 1
Level 1

I have an interface on my PIX520 assigned to my RAS dial up network. Presently, I have all ports opened up for traffic coming from that RAS interface to my inside. I need to determine which ports I need to keep open to allow my dial up users to work. Does anyone have suggestions or a config similiar to this who can help me out ?

Thanks

2 Replies 2

bbaley
Level 3
Level 3

It depends on what services they’re accessing. We have our RAS on the inside behind our PIX so we don’t have to open holes through the firewall. Depending on your topology, this may or may not work for you. In any case, determine what applications they’re using (NetBios, WINS, HTTP, Telnet, FTP, etc.) and open up the ports and protocols specifically.

jwitherell
Level 1
Level 1

I'd put a protocol analyzer in place with the RAS device, and see what traffic patterns you end up with. You'd probably be able to make some good conclusions in a few days as to what ports should be open.

Review Cisco Networking for a $25 gift card