Brilliant answer, thanks Viconsul.
I understand the difference between my static mapping the one you suggested is that mine maps all traffic coming on the public IP to private IP and traffic is then allowed on the basis of ACLs and yours only maps the required port (ACL still required), right...
Update:
I just noticed the first line access-list shows "deny ip any any" and not "deny tcp any any" so this may be totally irrelevant and not have an effect on the other access-lists below it which have tcp as the protocol. Confirmation anyone?
Hi Experts
Can someone confirm please if PIX access-lists are processed top to bottom. If yes, how can I change the order of the access-lists?
My config includes the following three lines in the same order as shown below.
access-list acl-outside deny ip any any
access-list acl-outside permit...
Hi Viconsul and others, need help again.
I have done a static mapping from the public IP to the private IP and then set up two access list entries to allow http and https traffic in to the server on LAN. However, this is not working.
I feel this is because the pix access lists are processed in...
Thanks Viconsul, you guys do know your stuff.
I sorted it by entering configure terminal. Conf t does the same thing, I guess. And en for enable's cool too.
Another quick question if I can ask you. I've just read about the Pix Device Manager. What are your thoughts on it?
Shall I set it up on...
Hi Experts
I'm new to Pix and trying to set up a static translation to map a public IP to a private IP using the static command. I have used the enable command to get into enable mode already.
At the prompt that looks like [firewall02#] I'm entering command as it looks below
firewall02#...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.