Solved

X-Box forwards thru a PIX 501

Posted on 2007-03-24
3
195 Views
Last Modified: 2010-04-09
Ok, I have the PIX 501 up and running (thanks to Barty Boy) New problem. This replaced the Linksys Wireless router AP we were using. Well now with the Pix in and up, the family is experiencing problems with their X-Box 360. Their are a few port forwards that need to be added, however I have no clue the format or how to do it bi-directional. 2 UDP Ports and one TCP port.
0
Comment
Question by:psd_steve
3 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 500 total points
ID: 18784919
Unless you have an access list applied to the inside interface, you should not have to worry about opening up any ports outbound to the Internet from the inside.  This should be implicitly allowed already.  However, look for the following command (or something similar) in your PIX config:

access-group inside_access_out in interface inside

If you see an "access-group" command with the last word referencing the "inside" interface, then you have an ACL applied to the inside interface that will need to allow the ports outbound.

As for allowing ports inbound from the Internet, you should have an access list already applied to the outside interface and it will be listed in a similar access-group command referencing the "outside" interface.  Let's say the name of the ACL is "outside_access_in".  Here is the syntax for opening up a port from the outside:

static (inside,outside) tcp interface 80 192.168.1.1 80 netmask 255.255.255.255
access-list outside_access_in permit tcp any interface outside eq 80

The first command configured port forwarding of TCP 80 (www) from the PIX public interface IP address inbound to host 192.168.1.1 on the internal network.  The second command ALLOWS the traffic on TCP 80 to flow inbound to that public IP address (the interface of the PIX itself).  It's not enough to just have one of those commands or the other, you have to have both.  So, for your example of 2 UDP ports and one TCP port, here is a template of what you should have:

static (inside,outside) udp interface <UDP_port_1> 192.168.1.1 <UDP_port_1> netmask 255.255.255.255
static (inside,outside) udp interface <UDP_port_2> 192.168.1.1 <UDP_port_2> netmask 255.255.255.255
static (inside,outside) tcp interface <TCP_port_1> 192.168.1.1 <TCP_port_1> netmask 255.255.255.255
access-list outside_access_in permit udp any interface outside eq <UDP_port_1>
access-list outside_access_in permit udp any interface outside eq <UDP_port_2>
access-list outside_access_in permit tcp any interface outside eq <TCP_port_1>

The first 3 static commands implements port forwarding for the 2 UDP ports and 1 TCP port (substitute the ones you need) and the last 3 access list statements allows those three ports inbound to host 192.168.1.1 on the inside.  This internal IP address should be the Ip address of your X-Box.

Hope this helps...
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Lync - CUCM Integration Question 2 26
WAN Site Edge Routers 15 56
Cisco Policy based routing 2 38
Cisco ASA 3 25
This is about downgrading PIX Version 8.0(4) & ASDM 6.1(5) to PIX 7.2(4) and ASDM 5.2(4) but with only 64MB RAM and 16MB flash. Background: You have a Cisco Pix 515E which was running on PIX 7.2(4) and its supporting ASDM 5.2(4) without any i…
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now