Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX and FTP Access

Status
Not open for further replies.
Dec 20, 2004
18
0
0
US
Hello!

I "need" to configure our PIX firewall to allow FTP from an AS400 to a customer. Is this a good (read: secure) thing to do and if so, is this the correct way to do it:

static (inside,outside) 208.xxx.xx.x 10.1.xx.xx puts AS400 on the outside for registered ftp outbound only??

Do I need a conduit permit statement as well?? If so what would it look like?

Thank you!!
 
you will need an ACL to allow FTP to pass thru the PIX.

access-list 100 permit tcp any host 208.x.x.x eq 21

No need for a conduit statement. Just add the statement above.
 
* agreed...

Conduits= bad

Anytime you want to provide a service to the outside you require a static & ACL.

Where is the AS400 in regards to the PIX (inside/outside/dmz)?

Also look to see that fixup for FTP is enabled, or FTP will break :).

Best regards,
Ryan Lindfield
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top