URGENT PIX Config Assist

Posted on 2005-04-27
Last Modified: 2010-05-18
Im normally quite confident with pix configuration but my brain has melted and i need some detailed Specific assistance.

I need to modify an access list, and other areas so a command line by command line guide would be great.

Situation. Need to reconfigure the PIX ACL to do the following. Allow all UDP and TCP traffic on all ports from any internal IP address list to go out side to a specific IP address list.

This Specific Address is of course NAT for a different networks internal IP address.

That same Specific Address must be allowed to come back using all TCP and UDP ports or ANY communication channels or ports back into the INTERNAL network of the main site.

EG my pc has to ping an ip address of a computer on the internal network of a remote site and vica-versa. Of course all the relvant chatter between thoose 2 different IP address on differing subnets are hidden behind NAT.

At the moment both sites can ping the public address which is great however due to the PIX this side nobody can ping or be pinged on an internal network. I need to change that for this 1 specific Address.

I would use PDM but this PIX doesnt have it and i have to use Command Line.. and as i said my brain is in a current state of melt DOWN.

A rating will be awarded. maximum amount of points for an URGENT ACCURATE response.

Thank you for your time.
Question by:rabelle
    LVL 79

    Accepted Solution

    Do you have extra public IP addresses?
    Yes ->Go to steps below
     Sorry, no such luck

    1. assign a static 1-1 nat xlate
       static (inside,outside) <public ip> <your pc ip> netmask
    2. Create access-list entry (use existing inbound acl)
      access-list outside_access_in permit ip host <their public ip> host <your nat static public ip>


    Author Comment

    ok slight revision to the above.

    there is a box in whats basically the dmz. It plugs into the network directly,  and also into a dirty switch

    because it plugs into the dirty switch it has a public and private address.
    the public address can be pinged
    the private address for that box alone can be pinged too
    but nothing else on the network

    its still the pix preventing everything because the pix is the default gateway for the network. i just need to configure the pix so that all traffic going to say 192.168.1.x goes to which then throughs it straight out into the remote site and to allow all traffic from to access the internal network.

    Author Comment

    oh that still works regardless... hmm ill get right on to it i think that will work fine just going to test.. brb..

    told you... brain is fried

    Author Comment

    Seems ok..... is it alright if i leave this open just a little longer? just to doubly make sure... then ill accept

    Author Comment

    Ok im not sure. here is the deal

    Router with public address.
    Dirty Switch DMZ basically
    VSR box plugged into DS with a public addy of on wan port
    VSR box plugged into Safe Switch with IP addy of
    the PIX box is obviously protecting all the safe switches.
    I can ping their public address
    they can ping the public address and the private address of the VSR box but nothing else.

    What commands do i need to put in to allow their internal network which is a 192.168.1.X network to go through that configuration and ping something on the 172.30.X.X network without problems

    Featured Post

    Top 6 Sources for Identifying Threat Actor TTPs

    Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

    Join & Write a Comment

    This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
    Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    14 Experts available now in Live!

    Get 1:1 Help Now