Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

ACL help needed

Posted on 2009-04-09
2
Medium Priority
?
278 Views
Last Modified: 2012-05-06
Have a 2621 router connected to a pix.

The 2621 is running netflow and i need to get it into the internal network. What I have isn't working. Help. Info as follows:

outside interface of router 67.13.72.202
Inside interface of router 67.133.189.193

outside interface of pix 67.133.189.200

ip of netflow server: 172.16.1.20
inside interface of pix 172.16.1.50
on the router:
 
static route:
ip route 172.16.1.20 255.255.255.255 67.133.189.200
 
 
on the pix:
access-list outside-to-inside line 32 extended permit udp 67.133.189.193 255.255.255.255 host 172.16.1.20  eq 2055 log

Open in new window

0
Comment
Question by:dissolved
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 2000 total points
ID: 24110553
You need to NAT the traffic through the Firewall.

Easiest thing to do is point netflow on the router to the outside of the PIX (67.133.189.200) and use the following PIX config:

access-list outside-to-inside extended permit udp 67.133.189.193 255.255.255.255 host 67.133.189.200  eq 2055 log

static (inside,outside) udp interface 2055 172.16.1.20 2055 netmask 255.255.255.255
0
 

Author Closing Comment

by:dissolved
ID: 31568692
u da man~!!!!!!
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

New Server 172.16.200.2  was moved from behind Router R2 f0/1 to behind router R1 int f/01 and has now address 172.16.100.2. But we want users still to be able to connected to it by old IP. How to do it ? We can used destination NAT (DNAT).  In DNAT…
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question