I finally figured this out. Unfortunately it really had nothing to do with the PIX. Our network administrators in their infinite wisdom have apparently blocked initiating incoming connections on port 80. Given that my server was of course listening on port 80 this was the source of the problem...
Here is the lates copy of my config. Note that the "any any" settings on the outside interface are temporary for debugging. I know that I need to changes these for production.
Thanks much for your help so far.
PIX Version 6.2(2)
nameif ethernet0 outside security0
nameif ethernet1...
Hi,
From my internal net I can get to the 192.169.1.90 server with no problem. It is a web server and I can access all the web services on the machine internally. I can access it locally and from any other box on the same internal net and I can also ping the server from the PIX console. The...
When I try to connect to the server using telnet 'outside ip' 80 I get "could not open a connection to the host on port: connection failed. Still no debug activity showing up.
Interesting enough however, if I try to telnet to port 23 it does not of course connect but I do see the attemp...
I tried the 'any any eq 80' and still no luck. This looks like a strange one. Based on the docs and your feedback I think I understand how this works now but I am still not getting the expected results. Can you think of anything else I should try?
Also, anyides why I do not get any debug...
Thanks for the reply. As far as I can see, port redirection is the solution that baddos had suggested also. I have made these configuration changes and still I am not getting through to my server. I have gotten to the point where I can ping the interface with the static command defined and the...
Hi,
I added the commands you suggested above, replacing 192.169.1.90 with the ip address of my inside server. Although the pix is no longer shutting down all traffic it still is not letting outside traffic into the web server. I have noted a couple of things that may be of interest.
Prior to...
Hi,
Is their another option besides using static to allow outside connections to an inside server?
Also, can you explain a little as to why a second IP address is needed when static is used? I am assuming you are saying I would need another internet registered IP address.
Thanks.
Hi,
I am trying to allow outside access to a server that is on the inside protected net. I am adding the static and access-list commands to a working config. Each time I add the static command the pix stops working in either direction. No traffics comes in or goes out. The goal is to add access...
It looks like this might infact come down to an authentication problem. I seem to be getting closer but have not yet solved it. I am trying to work through the various authentication options. Can anyone tell me if when using pre-share is any other authentication setup required other than...
Does anyone know if it is possible to retrieve debug statement output via a PDM session? If not are thier any other known methods of performing remote debug. I am using pix os 6.2 with pdm 2.1.
Thanks in advance,
w
I made the ip range changes and checked all the other areas commented on and I am still getting the same results...
I noticed a couple of other post on the board with users configuring VPN using the PDM and it not working. Has anyone ever been able to get this to work starting with the base...
Hi,
I am currently trying to set up VPN access on my pix 506e running 6.2os. I configured the box using the PDM wizard. I am uable to make a connection using Cisco VPN client 3.6.3.
On the client side I get a peer not responding message. On the pix I think the most significant debug message I...
Hey Bad Dos,
The missing DNS entry was the problem. Name resolutin is now working on my inside network. Thanks much for your help. Now I need to go figure out how to shut down all those holes I opened up trying to make this thing work.
Thanks again,
W
I know abbout the access list. I only have it set up that way as I am trying to resolve this problem.
I am not able to access resolved names(www.somedomain.com). That is the key problem. Maybe I phrased it wrong in my original message. What is to config param to associate the DNS server with...
Hi,
I am new to the Pix world and I am having a problem setting up my pix to allow Internet access from the inside. So far I have gotten to the point where I can ping an ip address on the public network(outside) in the form of x.x.x.x from inside my firewall. I can also ping my outside...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.