Solved

X-Box forwards thru a PIX 501

Posted on 2007-03-24
3
197 Views
Last Modified: 2010-04-09
Ok, I have the PIX 501 up and running (thanks to Barty Boy) New problem. This replaced the Linksys Wireless router AP we were using. Well now with the Pix in and up, the family is experiencing problems with their X-Box 360. Their are a few port forwards that need to be added, however I have no clue the format or how to do it bi-directional. 2 UDP Ports and one TCP port.
0
Comment
Question by:psd_steve
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 500 total points
ID: 18784919
Unless you have an access list applied to the inside interface, you should not have to worry about opening up any ports outbound to the Internet from the inside.  This should be implicitly allowed already.  However, look for the following command (or something similar) in your PIX config:

access-group inside_access_out in interface inside

If you see an "access-group" command with the last word referencing the "inside" interface, then you have an ACL applied to the inside interface that will need to allow the ports outbound.

As for allowing ports inbound from the Internet, you should have an access list already applied to the outside interface and it will be listed in a similar access-group command referencing the "outside" interface.  Let's say the name of the ACL is "outside_access_in".  Here is the syntax for opening up a port from the outside:

static (inside,outside) tcp interface 80 192.168.1.1 80 netmask 255.255.255.255
access-list outside_access_in permit tcp any interface outside eq 80

The first command configured port forwarding of TCP 80 (www) from the PIX public interface IP address inbound to host 192.168.1.1 on the internal network.  The second command ALLOWS the traffic on TCP 80 to flow inbound to that public IP address (the interface of the PIX itself).  It's not enough to just have one of those commands or the other, you have to have both.  So, for your example of 2 UDP ports and one TCP port, here is a template of what you should have:

static (inside,outside) udp interface <UDP_port_1> 192.168.1.1 <UDP_port_1> netmask 255.255.255.255
static (inside,outside) udp interface <UDP_port_2> 192.168.1.1 <UDP_port_2> netmask 255.255.255.255
static (inside,outside) tcp interface <TCP_port_1> 192.168.1.1 <TCP_port_1> netmask 255.255.255.255
access-list outside_access_in permit udp any interface outside eq <UDP_port_1>
access-list outside_access_in permit udp any interface outside eq <UDP_port_2>
access-list outside_access_in permit tcp any interface outside eq <TCP_port_1>

The first 3 static commands implements port forwarding for the 2 UDP ports and 1 TCP port (substitute the ones you need) and the last 3 access list statements allows those three ports inbound to host 192.168.1.1 on the inside.  This internal IP address should be the Ip address of your X-Box.

Hope this helps...
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco 3800 series and WISM2 1 40
Cannot connect to wireless using RADIUS 16 64
NTP configuration on Cisco switch 3 35
Moving vSAN traffic to a new network 4 67
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question