Solved

Open Ports in PIX 501 through PDM not command Line

Posted on 2004-09-27
6
1,959 Views
Last Modified: 2008-01-09
Hi
I have a PIX connected to ADSL Router Which is connected to MY ISP i use dynamic IP On my ADSL.

I wan to open ports 5500 & 9830 for inbound and outbound traffic both.

Please advise how is it possible through PDM.

I am very new to PIX and i cannot post my PIX configuration now any advise would be highly appreciated.

Thanks
M. Yasar
0
Comment
Question by:mivbinfotech
  • 3
  • 2
6 Comments
 
LVL 2

Author Comment

by:mivbinfotech
ID: 12159083
Gorgot to mention its PIX 501
0
 
LVL 3

Accepted Solution

by:
snoopy13 earned 250 total points
ID: 12167431
Hi,

for outbound traffic you do not have to do anything as by default everything is allowed from inside to a lower securiy interface (outside) so if the connection is initiated from the inside you will be fine. However if you are trying to connect from outside in you have to present the host you are trying to get to on the outside world this is done by a static.

static (insidie,outside) 217.publicIP 10.2.1.1(privateIP) netmask 255.255.255.255 0.0

then you will have an outside access-list
                                                  source IP     destination IP  
access-list outside permit tcp host 62.x.x.x host 217.publicIP eq 5500
access-list outside permit tcp host 62.x.x.x host 217.publicIP eq 9830

apply the access-lits to the outside interface
access-group outiside in interface outside




0
 
LVL 2

Expert Comment

by:parbul
ID: 12210549
Four outbound traffic not exist a problem, the default is permit all outbound traffic

For inbound traffic you need 3 steps.

1.- Configure a Static NAT or Port Forwarding in your adsl router
2.- Configure a access-list in the pix firewall when you permit the trafic
3.- Configure a Satic NAt o port forwarding in the pix.

0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 2

Author Comment

by:mivbinfotech
ID: 12210686
how to configure in the router and pix the port forward what do u mean exactly by this please advise.

One more thing i want to voice chat on msn which i am unable to do through PIX.  Please advise what port numbers do i have to allow inbound for MSN Voice chat to work through PIX .

Thanx in advance

Yasar
0
 
LVL 2

Expert Comment

by:parbul
ID: 12212446
Hi.

How configure in the adsl router depend  the vendor and model.   ¿Where you put the login and password of your adsl account?  (in de pix or the adsl router).

Port Forwarding is like a Static Nat  ( match outside ip to inside ip)  but in port forwarding only translated specific ports  and in the static nat  you match all the ports.

In the PDM of pix  the  port forwarding is configured in:

Main -> Configuration -> Translation Rules
Rules -> Add ->  put your internal ip and mask 255.255.255.255,  ->  select static and select Interface -> Select the Redirect port box,  select TCP and put 5500 in both boxs,  
Do the same for the port  9830

0
 
LVL 2

Author Comment

by:mivbinfotech
ID: 12276432
i opened different port nos though i used ur syntax it helped a lot thanx once agaoin u get the points

0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Concerto provides fully managed cloud services and the expertise to provide an easy and reliable route to the cloud. Our best-in-class solutions help you address the toughest IT challenges, find new efficiencies and deliver the best application expe…
Need to grow your business through quality cloud solutions? With everything required to build a cloud platform and solution, you may feel like the distance between you and the cloud is quite long. Help is here. Spend some time learning about the Con…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now