Do not use on any
shared computer
July 25, 2008 04:12pm pdt
null
[x]
Attachment Details

Access Lists in pix not working

Tags: CISCO, PIX506E
I have the following config to allow two things:

1.  VPN tunnel to 192.168.2.1 for our public IP 89.55.101.79
2.  Access to 192.168.2.24 (Voice mail Admin) from Public IP 89.55.101.78

The problem is I cant get both to work just either or.  Thanks

access-list outside_in permit udp host 10.124.XX.XXX eq 4500 host 89.55.101.79 eq 4500
access-list outside_in permit gre host 10.124.XX.XXX host 89.55.101.79
access-list outside_in permit esp host 10.124.XX.XXX host 89.55.101.79
access-list outside_in permit udp host 10.124.XX.XXX eq isakmp host 89.55.101.79 eq isakmp
access-list outside_in permit tcp any host 89.55.101.78 eq 4000
access-list outside_in permit udp any host 89.55.101.78 eq 4000

access-list outside_access_in permit tcp any host 96.56.110.78 eq 4000

static (inside,outside) tcp 89.55.101.78 4000 192.168.2.24 4000 netmask 255.255.255.255 0 0
static (inside,outside) udp 89.55.101.78 4000 192.168.2.24 4000 netmask 255.255.255.255 0 0
static (inside,outside) 89.55.101.79 192.168.2.1 netmask 255.255.255.255 0 0

access-group outside_in in interface outside
Start your free trial to view this solution
Question Stats
Zone: Security
Question Asked By: dupont2406
Question Asked On: 05.08.2008
Participating Experts: 1
Points: 500
Views: 0
Translate:
Loading Advertisement...
 
[+][-]Expert Comment by batry_boy

Rank: Sage

Expert Comment by batry_boy:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
[+][-]Author Comment by dupont2406
Author Comment by dupont2406:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
[+][-]Expert Comment by batry_boy

Rank: Sage

Expert Comment by batry_boy:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
[+][-]Author Comment by dupont2406
Author Comment by dupont2406:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
[+][-]Expert Comment by batry_boy

Rank: Sage

Expert Comment by batry_boy:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
[+][-]Author Comment by dupont2406
Author Comment by dupont2406:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
20080723-EE-VQP-34 / EE_QW_2_20070628