Solved

X-Box forwards thru a PIX 501

Posted on 2007-03-24
3
196 Views
Last Modified: 2010-04-09
Ok, I have the PIX 501 up and running (thanks to Barty Boy) New problem. This replaced the Linksys Wireless router AP we were using. Well now with the Pix in and up, the family is experiencing problems with their X-Box 360. Their are a few port forwards that need to be added, however I have no clue the format or how to do it bi-directional. 2 UDP Ports and one TCP port.
0
Comment
Question by:psd_steve
3 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 500 total points
ID: 18784919
Unless you have an access list applied to the inside interface, you should not have to worry about opening up any ports outbound to the Internet from the inside.  This should be implicitly allowed already.  However, look for the following command (or something similar) in your PIX config:

access-group inside_access_out in interface inside

If you see an "access-group" command with the last word referencing the "inside" interface, then you have an ACL applied to the inside interface that will need to allow the ports outbound.

As for allowing ports inbound from the Internet, you should have an access list already applied to the outside interface and it will be listed in a similar access-group command referencing the "outside" interface.  Let's say the name of the ACL is "outside_access_in".  Here is the syntax for opening up a port from the outside:

static (inside,outside) tcp interface 80 192.168.1.1 80 netmask 255.255.255.255
access-list outside_access_in permit tcp any interface outside eq 80

The first command configured port forwarding of TCP 80 (www) from the PIX public interface IP address inbound to host 192.168.1.1 on the internal network.  The second command ALLOWS the traffic on TCP 80 to flow inbound to that public IP address (the interface of the PIX itself).  It's not enough to just have one of those commands or the other, you have to have both.  So, for your example of 2 UDP ports and one TCP port, here is a template of what you should have:

static (inside,outside) udp interface <UDP_port_1> 192.168.1.1 <UDP_port_1> netmask 255.255.255.255
static (inside,outside) udp interface <UDP_port_2> 192.168.1.1 <UDP_port_2> netmask 255.255.255.255
static (inside,outside) tcp interface <TCP_port_1> 192.168.1.1 <TCP_port_1> netmask 255.255.255.255
access-list outside_access_in permit udp any interface outside eq <UDP_port_1>
access-list outside_access_in permit udp any interface outside eq <UDP_port_2>
access-list outside_access_in permit tcp any interface outside eq <TCP_port_1>

The first 3 static commands implements port forwarding for the 2 UDP ports and 1 TCP port (substitute the ones you need) and the last 3 access list statements allows those three ports inbound to host 192.168.1.1 on the inside.  This internal IP address should be the Ip address of your X-Box.

Hope this helps...
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco ASA 5512 LAN Config 16 78
Cisco ASA 5512-X Active/Standby HA 4 25
not able to to ping server on a switch 1 33
BGP recommended setup with failover 2 46
If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question