Solved

PIX 506e - Allow inbound traffic

Posted on 2004-04-01
6
873 Views
Last Modified: 2010-04-09
I am creating a new network nat'd behind a PIX 506e.  I still need to allow users in the original network to access the new network.  Outbound traffic works because the PIX allows this implicitly.  I will have to close this down in the near future.  I can't seem to allow any inbound traffic initiated from the outside.  The log shows  
 
 %PIX-3-305005: No translation group found for tcp src outside:55.55.55.55/2832 dst inside:10.0.0.1/445
 
Basically I want to allow everything from outside network 55.55.55.0/24 to the inside network 10.0.0.0/23.
0
Comment
Question by:bdebelius
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 45

Expert Comment

by:Kent Olsen
ID: 10735657


I believe that your access list entry should look something like this:



access-list 160 permit ip  55.55.55.0 0.0.0.255 10.0.0.0/23 0.0.1.255
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 10736346
Kdo, the access-lists on a PIX use subnet masks. You must be more familiar with the access-lists on a router that use an inverse mask...

access-list outside_in permit ip 55.55.55.0 255.255.255.0 10.0.0.0 255.255.254.0
access-group outside_in in interface outside

0
 
LVL 79

Accepted Solution

by:
lrmoore earned 250 total points
ID: 10736360
Oh, yes, assuming that you do not want to nat the traffic between 55.55.55.0 and 10.0.0.0, add these lines:

access-list no_nat permit 10.0.0.0 255.255.254.0 55.55.55.0 255.255.255.0
nat(inside) 0 access-list no_nat

0
Are You Headed to Black Hat USA 2017?

Getting ready for Black Hat next week? Kick things off with the WatchGuard Badge Challenge and test your puzzle and cipher skills. Do you have what it takes to earn our limited edition Firebox Badge? Get started today - https://crimsonthorn.net

 
LVL 45

Expert Comment

by:Kent Olsen
ID: 10737135

Good catch....

I don't care how these devices represent the mask values internally -- you'd think that at least the language syntax would be similar.


:-)

0
 

Author Comment

by:bdebelius
ID: 10741104
Thanks lrmooore.  That worked.  But I have another question(s) about this.

How would I change the configuration to nat the outside address, so that they appear to be coming from the inside interface?

What would be the reasons to do or not to do this?  I understand nat going outbound is to hide the inside network, but why would I want to hide the outside network?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 10744277
You can nat the outside if you have some overlapping addresses, or routing issues. Otherwise, I can't think of any good reason to do it.

I have done it when I want to get to a customer's private IP addresses and they overlap with another customer's private IP addresses.

0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question