Solved

configuring pix to allow terminal server from outside

Posted on 2007-11-30
6
231 Views
Last Modified: 2010-04-21
I have a new Pix 506e I have set up at a customer with 1 IP address how do I set it up so we can connect to the terminal server from the outside?  the Ip of the server is 192.168.1.200.

I have done this on a  pix with multiple IP addresses, but not on one with just one IP  please help!
0
Comment
Question by:mturnow
  • 4
  • 2
6 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 500 total points
ID: 20386429
Since you have only the one public IP address, which is presumably used on the outside PIX interface, here's how to do it:

static (inside,outside) tcp interface 3389 192.168.1.200 3389 netmask 255.255.255.255
access-list outside_access_in permit tcp any interface outside eq 3389
access-group outside_access_in in interface outside

This allows any Internet host to RDP into that machine, so I would specify individual source IP addresses for that access list for security reasons if you know what they are.
0
 

Author Comment

by:mturnow
ID: 20386453
what do you mean by:

so I would specify individual source IP addresses for that access list for security reasons if you know what they are
0
 
LVL 28

Expert Comment

by:batry_boy
ID: 20386582
Well, if the people that you want to be able to access the server via a remote desktop connection have a known public static IP address, then you would find out what that is and then structure your access list using only the static IP address for those users.  For example, if you had an external user that had 1.1.1.1 as a static public IP address, then you would use the following access list statement to only allow that source IP address (1.1.1.1) to access that server via remote desktop:

access-list outside_access_in permit tcp host 1.1.1.1 interface outside eq 3389

You would then put in one of those statements like above for every user that had a static public address.  This may not be feasible for your situation since the users you want to have access the server may not have static public IP addresses.  Make sense?
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 

Author Comment

by:mturnow
ID: 20388053
Yep makes sense.  I will give this a try Monday morning.  
0
 

Author Comment

by:mturnow
ID: 20395908
did not work, gave me an error
0
 

Author Closing Comment

by:mturnow
ID: 31412062
nevermind i retried and it worked beautifully
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Suggested Solutions

This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now