Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Newbie question about Pix 506 config.

Status
Not open for further replies.

Thilton

IS-IT--Management
Apr 23, 2003
31
US
Hello All,

Although I'm not new to firewalls I know practically nothing when it comes to the Cisco Pix 506. I have a client that has one and they are looking to replace it. I as looking at the configuration and was quickly confused about what I saw, specifically the following:

fixup protocol ftp 21
fixup protocol http 80
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol sip 5060
fixup protocol skinny 2000

What the heck does this mean? I know this is a simple question but I'm at a loss

Thanks!

Troy
 
the fixup protocals allow application the access the pix firewall via the that specific protocal
for example

fix protocol ftp 21 allow ftp traffic to flow throw the pix firewall.
fix up protocol http 80 allow the http traffic to flow through the pix
 
OK. it is necessary to have all of these visible if I'm only using http and SMTP?

Troy
 
The fixups do different things depending on the fixup. Basically, they are application inspection commands that add a little bit of security to specific protocols.

For example, fixup smtp 25 restricts mail communication to a few basic SMTP commands (i.e. no ESMTP stuff) in the name of security. Fixup FTP is used to manage all the dynamic connections created by and an active (vs. a passive) FTP connection.

In theory, you could turn off the fixups and SOME of the protocols would still work. For example, if you turned off the fixup FTP, passive FTP would still work, but no inbound FTP would.

I say "in theory" because it's almost always a good idea to leave them in there.

If you want to read more about them:
 
Thanks! That explains a lot. I'll look at the article.

Troy
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top