Solved

cisco pix accept traffic only from one ip address

Posted on 2008-10-02
4
246 Views
Last Modified: 2010-04-09
Hello, we have a cisco pix 525 and we want to restrict an external ip address from only accepting traffic from one vendor. what would I need to do to do that. i'm fairly new at configuring firewalls and I dont want to open anything that would risk the network. alll comments are appreciated. thank you.
0
Comment
Question by:hherrera
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 23

Expert Comment

by:debuggerau
ID: 22629751
I use accesslists to control permissions in and out. For a particular vendor who needs access to a machine, I just enable an accesslist for a particular time period from a particular IP address (assuming you dont want them to have VPN) through to the machine in question, then they can remote desktop or whatever in..

Do you have the ADSM Launcher for the PIX, it makes configuring it a whole lot simpler and convenient?


0
 

Author Comment

by:hherrera
ID: 22629804
thank you for your comment. can you please guide me on how to get hte adsm launcher and the instructions on how to create the access list with restricitons on the ip address. thank you.
0
 
LVL 23

Accepted Solution

by:
debuggerau earned 90 total points
ID: 22629900
the adsm may have been already loaded, check out the address of the PIX from a browser, using https://<pix ip address>
Else, you'll need a cisco account to get it from their website.

Can you telnet into the PIX, as it can be done from the command line.

access-list outside_access_in extended permit ip host <vendors ip address> host <your external ipaddress> time-range <Vendors time access>

Start with out time for a test, i.e.
access-list outside_access_in extended permit ip host <vendors ip address> host <your external ipaddress>

0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22631076
The thing debugger AU forgot is the access-group command to apply the access-list and make it active.
Can you please post your config? You can get this by running the sh run  command from the command line while at the # prompt. Please copy it and paste it here so I can review it and tell you the appropriate changes to make.
Cheers!
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
replacing 2811 to ISR 4331 2 79
snmp v2 configuration on a switch 3 61
Cisco tacacs question 6 53
Cisco WAP551 and Guest Users 6 15
Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question