06-14-2002 08:09 AM - edited 02-20-2020 10:05 PM
I have an interface on my PIX520 assigned to my RAS dial up network. Presently, I have all ports opened up for traffic coming from that RAS interface to my inside. I need to determine which ports I need to keep open to allow my dial up users to work. Does anyone have suggestions or a config similiar to this who can help me out ?
Thanks
06-21-2002 07:17 AM
It depends on what services theyre accessing. We have our RAS on the inside behind our PIX so we dont have to open holes through the firewall. Depending on your topology, this may or may not work for you. In any case, determine what applications theyre using (NetBios, WINS, HTTP, Telnet, FTP, etc.) and open up the ports and protocols specifically.
06-21-2002 09:49 AM
I'd put a protocol analyzer in place with the RAS device, and see what traffic patterns you end up with. You'd probably be able to make some good conclusions in a few days as to what ports should be open.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide