Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Opening ports on PIX

Status
Not open for further replies.

ntwrkrbkj

IS-IT--Management
Jun 2, 2003
58
I am setting up video conferencing on a machine in my network. I know I can do port forwarding on the router, but is there anyway to open the ports I need on the PIX firewall for just one machine? Or would I have to open them for the entire network?
 
You can specify 1 address in the ACL, by using the host keyword. This way you could limit the connection to just 2 addresses.
access-list 100 permit IP host 1.2.3.4 host 192.199.99.9 where 1.2.3.4 is the users source address, 192.199.99.9 is the outside pix address defined in your static. If you know the IP protocol (UDP/TCP) and port numbers you can imprve the ACL security by including these parameters.


If your outside user is connecting via an ISP then you'll find that each time they connect they may be given a different IP address picked out of the ISP's allocated range. This makes the ACL configuration a bit more difficult. If this is a problem then you may be able to get around it by using a VPN connection, this way you can control the IP address you allocate to the VPN client.
 
Ok, so basically I do the same thing on the PIX as I would on a router to open up ports? Awesome, I was betting it would be some weird command :).

I will have to open on the PIX and static map on the router though, right?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top