Opening up HTTP access to additional Webserver behind a PIX 515

Posted on 2006-05-06
Medium Priority
Last Modified: 2010-04-09
Hi, I have a webserver which I just added to our network which I am trying to grant access to from the outside.  I added the following lines to the pix configuration:

access-list outside_access_in permit tcp any host eq www
static (inside,outside) netmask 0 0

I have another webserver which is currently accessible which looks to be using the same syntax as this but with different external/internal addresses for other webserver; however this one that I just added is not accessible.  Am I missing something from this config?

Thank you!
Question by:jfexchange
  • 2
LVL 79

Expert Comment

ID: 16621035
Did you clear xlate after adding the static?
Did you re-apply the access-group to the interface?

pixfirewall(config)#clear xlate
pixfirewall(config)#access-group outside_access_in in interface outside

Did you verify the correct IP address, subnet mask and default gateway on the server? Does it point to the PIX IP as its default gateway?

Author Comment

ID: 16621451
Thanks for the quick response, I did verify the IP and clear the xlate.  I didn't think I need to re-apply the access-group on the pix, but I just did that now and recleared the xlate and it still is not working.

Could it be anything else?
I was given the external IP address to use by someone else, I think maybe it is not valid?
LVL 79

Accepted Solution

lrmoore earned 2000 total points
ID: 16621592
>I was given the external IP address to use by someone else, I think maybe it is not valid?
It absolutely must be given to you by your ISP, not anyone else.
It should be in the same range as the outside interface of the PIX

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month14 days, 7 hours left to enroll

807 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question