troubleshooting Question

Pix 506 E Multiple Port Configuration

Avatar of hexvader
hexvaderFlag for United States of America asked on
RoutersSoftware FirewallsCisco
1 Comment1 Solution751 ViewsLast Modified:
Experts,
I have a client who is using a pix 506e as a firewall.  They are getting a new phone system and the installing company has asked them to open the following ports:

5060 – UDP/TCP
•         5004 – UDP/TCP
•         10000-10201 - UDP

I was able to set these up in the access list by using a group-object based on this article:
https://www.experts-exchange.com/Hardware/Networking_Hardware/Firewalls/Q_23210702.html

However, at the bottom of this artilce, it states I have to manually static map each of the
200 plus ports in the 10000 - 10201 range.  Here is the text from the above article:

object-group service group_1 tcp-udp
  port-object range 1717 1723
access-list outside_access_in permit tcp any interface outside object-group group_1

but then you need a static for every port!!!

static (inside,outside) tcp interface 1717 10.10.10.4 1717 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1718 10.10.10.4 1718 netmask 255.255.255.255 0 0

etc

There is no way of creating 1 static mapping - for ex>

static (inside, outside) tcp interface etc ......

to list all these ports ?

Please advise.
Thanks
John
ASKER CERTIFIED SOLUTION
Pete Long
Solutions Architect
Join our community to see this answer!
Unlock 1 Answer and 1 Comment.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 1 Comment.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros