Solved

Opening ports too difficult on Cisco PIX router

Posted on 2007-03-28
4
223 Views
Last Modified: 2010-04-17
Well, I will try again. Very simple. How do I add an Access list, so I can receive traffic on a certain port like 443, etc. I get to the Cisco PIX 501 V6.3 and PDM V3 and the configuration screen and the Access tab. I then click on Rules and Add, and I am lost. Is that the window where I add incoming ports? If so, how do I do it exactly. I do not wish to do this at a command, only on the PDM if possible.

May I add this is the single hardest thing I have tried to learn to do. I cannot find a good article on it anywhere. It simply can't be that difficult, can it? Thaniks
0
Comment
Question by:Bert2005
  • 2
4 Comments
 
LVL 5

Expert Comment

by:drawlin
ID: 18813874
I enjoy the ease of the GUI also but never forsake the CLI.  GUI's change often, but the commands stay the same.  If you already have an access list configured, it is so easy to type "show access-list" and copy and paste that into a text file.  Then you can modify the ports and paste the command back into the CLI at the config terminal.

Something like

login, then:

enable
config t
access-list inbound allow tcp all 192.168.2.100 eq 443

you can find samples everywhere on the web for the syntax
0
 
LVL 28

Accepted Solution

by:
mikebernhardt earned 500 total points
ID: 18819891
You're in the right area. But before you click add a rule, you need to define the host you want to allow access to, under hosts and networks. Define it as part of the inside.

THEN add a rule and permit traffic from any on the outside to the host you just defined on the inside. Select tcp and the destination port.

If you want to allow a bunch of protocols to permit to the host, create a service group and list all the protocols. Then in your rule, permit the service group.
0
 
LVL 1

Author Comment

by:Bert2005
ID: 18820859
MIke,

Thanks. But, you still give me too much credit. I see a place where it says Source/Host Network with IP address configured by default. I then see Name and Group to the right. Below that is Interface which states "inside" with IP Address and Mask.

Is there where I define a host? And, if so, can you tell me in detail.

I apologize for my ignorance. At least I did purchase it, configure it and set up a VPN with it, but that was with a wizard.

Thanks.
0
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 18824660
You will find everything you need to know in this document:
http://www.cisco.com/application/pdf/en/us/guest/products/ps2032/c1626/ccmigration_09186a00804ec67b.pdf

It's a PDF, so you can download and print it.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Can Cisco resolve internet address internally 4 34
anyconnect password change 2 33
Cisco IP NAT Translation not working 9 26
Ping Through ASA Firewall 6 23
If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now