Link to home
Start Free TrialLog in
Avatar of Shakthi777
Shakthi777Flag for Afghanistan

asked on

Cisco PIX 515E forwarding rule HELP !

Hi Experts,

My Device:
Cisco PIX515E
PIX Version: 8.0(4)

I just need to know the possibility of following and example rule if it's possible.

I have below rule already placed in my PIX and I need to add additional rule for the same public IP

2x2.x.5x.55 port 4000 to 192.168.4.10 port 4000

Please advise and thanks a lot for your time !
#######What is have in my access list currently#######

access-list 110 extended permit tcp any host 2x2.x.5x.55 eq www
static (inside,outside) tcp 2x2.x.5x.55 www 192.168.4.8 4000 netmask 255.255.255.255
########################################################

Open in new window

Avatar of Istvan Kalmar
Istvan Kalmar
Flag of Hungary image

Hi,

This rule is good, go ahead!

Best regards,
Istvan
Avatar of Shakthi777

ASKER

Actually I need to place the second rule for 2x2.x.5x.55 port 4000 to 192.168.4.10 port 4000

How can I do that ?
please show the comnfig
sry my mistake !

#######What is have in my access list currently#######
access-list 110 extended permit tcp any host 2x2.x.5x.55 eq www
static (inside,outside) tcp 2x2.x.5x.55 www 192.168.4.8 4000 netmask 255.255.255.255
########################################################

#######Second rule I need to place for the same public IP#######
Traffic from 2x2.x.5x.55 port 8080 to 192.168.4.10 port 8080
########################################################

Open in new window

ok you need:


access-list 110 extended permit tcp any host 2x2.x.5x.55 eq 8080
static (inside,outside) tcp 2x2.x.5x.55 www 192.168.4.8 4000 netmask 255.255.255.255
clear xlate
ASKER CERTIFIED SOLUTION
Avatar of Istvan Kalmar
Istvan Kalmar
Flag of Hungary image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
thanks a lot ikalmar, let me chk and confirm !

btw both rules should function well with the same public IP !
worked well !