Solved

How do I get my website on the web using a PIX501 (via the PDM) and a DNS forwarding service (www.no-ip.com)?

Posted on 2004-09-07
9
340 Views
Last Modified: 2010-04-11
I'm currently using www.no-ip.com for DNS forarding and a Cisco PIX501 to get my website on the internet.  The issue is that no matter what I do it won't get through my firewall, or so it seems.  I did a port scan to see if port 80 was open from the web and it appears to be closed/secured/stealth.  I'm using Windows 2003 Server Standard Edition with IIS 6.0, the server is a DC running DNS.  I beleive I created the right rules on the router but I can't get this to work.  FYI, I'm using the PDM, not the command interface, I'm fairly new to the PIX501 but do have a little excperience.  Also, I used to use a Linksys router and the website went through fine, I wonder if it is a combination of the firewall and IIS6.
0
Comment
Question by:copio
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
9 Comments
 
LVL 5

Expert Comment

by:rsriprac
ID: 12001644
I would start off by connecting on a regular hub and see if you could connect to the webserver.  If it does connect, then its obviously the PIX unit,  if not then your IIS is not worrking properly.

"I wonder if it is a combination of the firewall and IIS6."

This would be impossible since they sit on different layers, if IIS is working then it is definitly the firewall.  On the firewall, try turning off all protection and see if that makes a difference.  Also try to connect to the webserver via IP and not by its name since you might have some DNS problems.

I suspect it is the PIX firewall, but try out the different tests and reduce it to the PIX firewall.  So if it is the PIX firewall, then like I mention, open all the ports on the firewall and it should work.  Then from there start to shut down the various ports.

Make sure the rules are proper also.  HTTP uses port 80 for incoming request but for it outgoing, it might send it out on different ports. One thing that might help is running a packet/network analyser like ethereal (http://www.ethereal.com/) and see exactly whats going on.

I hope this helps,

-Ram
0
 
LVL 23

Assisted Solution

by:Tim Holman
Tim Holman earned 240 total points
ID: 12004758
I would follow the instructions here for basic WWW server setup behind a PIX:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a008009402f.shtml

It would be easier for us to assist with the command line config, rather than PDM, as there is no way for you to show us a snapshot of the PDM config as it's GUI / interactive.
0
 

Author Comment

by:copio
ID: 12029734
I beleive I have everything setup, however I can't get to port 80 inbound from the web therefore my website is not accessible.  How do I open port 80 on the PIX501?  I ran a port scan from the outside and it shows that port 80 is closed/stealth.  Thanks...
0
SuperAntiSpyware Licenses Discounted by 25% !

Exclusive offer to Experts Exchange Members!
Buy SuperAntiSpyware License(s) from us and save 25% on the regular purchase price.
- Includes Full SuperAntiSpyware Vendor Support Entitlements
- Your Subscription does not begin until you activate your license
- Buy for your friends

 

Author Comment

by:copio
ID: 12029759
Do I need to use the DNS entries from www.no-ip.com as well?  I don't think so, but thought I'd ask.
0
 
LVL 5

Accepted Solution

by:
rsriprac earned 260 total points
ID: 12030446
> Do I need to use the DNS entries from www.no-ip.com as well?  I don't think so, but thought I'd ask.

Yes if you do not have a static IP.

Also thie page have some information on allowing port 80:

http://www.siliconvalleyccie.com/cisco-hn/dsl-pix.htm

You need to create a access-list to allow port 80 to come through.

"Dynamic DNS Port Forwarding Entries
It is possible to host your own website on a DHCP DSL / cable modem connection using dynamic DNS. There are many providers to choose from.

Once you have registered with a dynamic DNS provider, you will need to configure your firewall. Here we allow all incoming www traffic (on TCP port 80) destined for the firewall's interface to be forwarded to the web server at 192.168.1.100 on port 80 (www).

 

access-list inbound permit icmp any any
access-list inbound permit tcp any any eq www

access-group inbound in interface outside
static (inside,outside) tcp interface www 192.168.1.100 www netmask 255.255.255.255

Once configured, you will be able to hit your webserver using the firewall's outside interface's IP address as the destination. eg: http://firewall-outside-ip-address. Remember, it's not possible to hit your firewall's public NAT IP address from servers on your home network. You'll have to ask a friend to check it out.
"


-Ram
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 12039272
Could you post up your PIX config, then we will fix it.  :)
0
 

Author Comment

by:copio
ID: 12162909
I'll get my PIX config and post so we can get to the bottom of this, I'm still having the same issue.  Sorry I haven't gotten but I'ev been busy.
0
 

Author Comment

by:copio
ID: 12193044
I'm going to close this out since I finally figured it out.  I had to do some work on the PIX and in the process my ISP shut down port 80, so I'm using a different port now and I'm all set.  They threw me for a loop because they shut down port 80 while I was troubleshooting this issue, port 80 use to be open.  The ISP is Optimum Online/CableVision.
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 12201679
That wasn't very nice of them !
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Ransomware continues to grow in reach and sophistication, putting data everywhere at risk. Learn how to avoid being caught in its sinister clutches with these 11 key tips.
Smart phones, smart watches, Bluetooth-connected devices—the IoT is all around us. In this article, we take a look at the security implications of our highly connected world.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question