?
Solved

ACL help needed

Posted on 2009-04-09
2
Medium Priority
?
276 Views
Last Modified: 2012-05-06
Have a 2621 router connected to a pix.

The 2621 is running netflow and i need to get it into the internal network. What I have isn't working. Help. Info as follows:

outside interface of router 67.13.72.202
Inside interface of router 67.133.189.193

outside interface of pix 67.133.189.200

ip of netflow server: 172.16.1.20
inside interface of pix 172.16.1.50
on the router:
 
static route:
ip route 172.16.1.20 255.255.255.255 67.133.189.200
 
 
on the pix:
access-list outside-to-inside line 32 extended permit udp 67.133.189.193 255.255.255.255 host 172.16.1.20  eq 2055 log

Open in new window

0
Comment
Question by:dissolved
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 2000 total points
ID: 24110553
You need to NAT the traffic through the Firewall.

Easiest thing to do is point netflow on the router to the outside of the PIX (67.133.189.200) and use the following PIX config:

access-list outside-to-inside extended permit udp 67.133.189.193 255.255.255.255 host 67.133.189.200  eq 2055 log

static (inside,outside) udp interface 2055 172.16.1.20 2055 netmask 255.255.255.255
0
 

Author Closing Comment

by:dissolved
ID: 31568692
u da man~!!!!!!
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

New Server 172.16.200.2  was moved from behind Router R2 f0/1 to behind router R1 int f/01 and has now address 172.16.100.2. But we want users still to be able to connected to it by old IP. How to do it ? We can used destination NAT (DNAT).  In DNAT…
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question