configuring pix to allow terminal server from outside

I have a new Pix 506e I have set up at a customer with 1 IP address how do I set it up so we can connect to the terminal server from the outside?  the Ip of the server is 192.168.1.200.

I have done this on a  pix with multiple IP addresses, but not on one with just one IP  please help!
mturnowAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
batry_boyConnect With a Mentor Commented:
Since you have only the one public IP address, which is presumably used on the outside PIX interface, here's how to do it:

static (inside,outside) tcp interface 3389 192.168.1.200 3389 netmask 255.255.255.255
access-list outside_access_in permit tcp any interface outside eq 3389
access-group outside_access_in in interface outside

This allows any Internet host to RDP into that machine, so I would specify individual source IP addresses for that access list for security reasons if you know what they are.
0
 
mturnowAuthor Commented:
what do you mean by:

so I would specify individual source IP addresses for that access list for security reasons if you know what they are
0
 
batry_boyCommented:
Well, if the people that you want to be able to access the server via a remote desktop connection have a known public static IP address, then you would find out what that is and then structure your access list using only the static IP address for those users.  For example, if you had an external user that had 1.1.1.1 as a static public IP address, then you would use the following access list statement to only allow that source IP address (1.1.1.1) to access that server via remote desktop:

access-list outside_access_in permit tcp host 1.1.1.1 interface outside eq 3389

You would then put in one of those statements like above for every user that had a static public address.  This may not be feasible for your situation since the users you want to have access the server may not have static public IP addresses.  Make sense?
0
What Kind of Coding Program is Right for You?

There are many ways to learn to code these days. From coding bootcamps like Flatiron School to online courses to totally free beginner resources. The best way to learn to code depends on many factors, but the most important one is you. See what course is best for you.

 
mturnowAuthor Commented:
Yep makes sense.  I will give this a try Monday morning.  
0
 
mturnowAuthor Commented:
did not work, gave me an error
0
 
mturnowAuthor Commented:
nevermind i retried and it worked beautifully
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.