Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Search results for query: *

  1. iiiiss

    Syslog ?!

    Thank you for the response ! I tried the kiwi server and now it works....
  2. iiiiss

    Syslog ?!

    HI ! I wanted to set up a syslog server to receive syslog messages from the PIX (515 with 6.2 (2)) I tried the syslogserver from cisco (pix firewall syslog server) but it received nothing! It seems that the Pix isn´t sending anything to the syslog server ! I used "logging host inside...
  3. iiiiss

    VPN / Is this possible ??

    Thanks both ! To Yizhar, it is because of the lack of public addresses ! Best Regards !
  4. iiiiss

    VPN / Is this possible ??

    Thanks for the reply ! Do you mean IOS or firmware ??? I didn´t know that I can upgrade the Firmware .. only the IOS .. I´m using the IOS version 6.2(2) You can do this by using a static command like " static(inside,outside) xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx" But that´s not what I...
  5. iiiiss

    VPN / Is this possible ??

    HI ! I would like to connect through my pix to another pix using the cisco vpn client. As I am using PAT I think I would need transparent tunneling for this but the pix doesn´t seem to support that and I don´t want to use static commandos ! Is it possible to solve this problem with the...
  6. iiiiss

    User based ACLs

    You can differentiate them by htere ip address ! You can use crypto map entries fr that and you can specify the username and the password with vpngroups ... Try searching in this forum, there were several threads for this issue.. Best regards Have fun
  7. iiiiss

    User based ACLs

    HI ! You can do it with "no sysopt connection permit-ipsec" and then use access-lists to permit access to the speficied destinations ! Hope that helps Best regards
  8. iiiiss

    Cisco PIX 515 (Any Experts out there?)

    I think when you don´t want to share your information, then you should either send only really neccesary informations (when more people have the informations you have a better chance to find a solution) or you should ask yizhar because I think he has the most experience of us ! Best regards
  9. iiiiss

    Cisco PIX 515 (Any Experts out there?)

    Hi ! Send what you want to do and what you need and we´ll see how we can help.. Best regards
  10. iiiiss

    PIX VPN no end in sight

    I got it. Thanks to microsoft ! I needed SP1 and several security updates for XP and now it works ! (only with the static command) Is it possible to vpn out of the PIX withouth using static ??? Thanks to everybody
  11. iiiiss

    Newbie ?

    Use PIxcript from http://come.to/yizhar for basic configuration !
  12. iiiiss

    Error Message Help

    You don´t want to do this ! I had a simlilar problem. The PIX doesn´t allow traffic that comes from the dmz to go to the inside !( exept the traffic that comes from inside) When you have to let traffic from the dmz to go to the inside , use:" static (inside,dmz) ........" but thats...
  13. iiiiss

    PIX VPN no end in sight

    Could that happen because I use several IP-pools (for each VPN client another pool) ?? THanks
  14. iiiiss

    PIX VPN no end in sight

    Yes I tried setting up a static and with this entry I can establish the vpn tunnel BUT I can´t do ANYTHING ! I can´t ping anything on the other side of the tunnel ! I don´t see anything in the logs ! What could I´ve done wrong ? any suggestions ? The tunnel can be established and I´don´t see...
  15. iiiiss

    Removing VPN Config.

    you can close them in groups... for example when you want to delete a vpngroup you just have to type "no vpngroup GROUPNAME" Or when you want to delete a cryptomap just write "no cry ma MAPNAME" Best Regards
  16. iiiiss

    squid access-list

    You just need to permit th etraffic you want you don´t have to deny traffic because the pix denies all traffic by default!
  17. iiiiss

    XLATE ?!

    Yeah was something .... but the IP addresses weren´t the same on the inside and the dmz because thats not possible but basically you are right.
  18. iiiiss

    Problem pinging own server external IP

    Please provide more informations (loggin ?, what exactly do you want to do, from where do you want to ping etc..) Best Regards
  19. iiiiss

    XLATE ?!

    Ok I think I figured it out myselfe... I just have to use a static command ... Thanks for the help. Best regards
  20. iiiiss

    Blocking Ports

    just use access-lists and access-groups ... eg: when you want to block access from inside to outside over port 5190 --> access-list inside deny tcp a a eq 5190 access-group inside in interface inside or when you want to block the ports from 5190 to 5193 access-l inside deny tcp any any...

Part and Inventory Search

Back
Top