Hello all,
I'm in a situation where I need to pass several IP ports through a pix 515. An microsoft server in a DMZ on the pix is to be restricted from sending only through a few ports, such as 135, 138, etc to other MS servers.
The prob is that I've run a network monitoring tool and also NETSTAT commands and it's seeing the DMZ server's outgoing port as a random # to connect to say 135 on the server outside the DMZ.
??? How does one put a conduit in then! It seems like the pix is not inspecting/blocking for destination but source port (which is random, ugh). How do I tell the pix to only look for the destination port in the packet, not the origin?
Thanks!
Peter Turek
power_pete@hotmail.com