Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Microsoft IP port conduits on pix 515

Status
Not open for further replies.

Peteksi

MIS
May 18, 2001
10
US

Hello all,

I'm in a situation where I need to pass several IP ports through a pix 515. An microsoft server in a DMZ on the pix is to be restricted from sending only through a few ports, such as 135, 138, etc to other MS servers.

The prob is that I've run a network monitoring tool and also NETSTAT commands and it's seeing the DMZ server's outgoing port as a random # to connect to say 135 on the server outside the DMZ.

??? How does one put a conduit in then! It seems like the pix is not inspecting/blocking for destination but source port (which is random, ugh). How do I tell the pix to only look for the destination port in the packet, not the origin?

Thanks!

Peter Turek
power_pete@hotmail.com
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top