Cisco PIX 501 - adding static group
Posted on 2004-04-27
I am fairly new to Cisco PIX and purchased one for home just so I could learn.
Because the PIX is running as a PAT device, where the external IP is dynamic I am having difficulty enabling inbound access easily.
For example if I want to open my internal webserver to the out side I have successfully achieved this with the folling commands.
static (inside,outside) tcp interface www 192.168.10.220 www netmask 255.255.255.255 0 0
access-list inbound permit tcp any interface outside eq www
However I want to create a new rule for bittorrent (I know I know)
I created an object group (see below)
object-group service bittorrent tcp-udp
port-object range 6881 6999
But when I try adding this
static (inside,outside) tcp interface bittorrent 192.168.10.250 bittorrent netmask 255.255.255.255 0 0
It does not recognise the bittorrent group.
Help me, I have IOS 6.3(3)