• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 437
  • Last Modified:

pix acl

i would like an external dns server from communicate with a to a internal dns server. on th pix 6.2.2 what would i need to do?
access-list 110 permit tcp host realip host 172.16.1.34 eq 56

hat are some commands to see if acls are working
0
cogit
Asked:
cogit
1 Solution
 
lrmooreCommented:
DNS does not use port 56, unless you have something special.

The syntax is:
  access-list 110 permit tcp host <external server ip> host <global IP> eq 53
  access-list 110 permit udp host <external server ip> host <global IP> eq 53

You would have to post your complete config for me to be more specific for you.

Any time you chang the acl, you have to re-apply it to the interface:
   access-group 110 in interface outside

To check it, use "show access-list" and look for (hitcount= )
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now