Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Pix device cannot access Msnbc.com

Status
Not open for further replies.

angels1

IS-IT--Management
May 17, 2003
68
0
0
US
I am not able to access msnbc.com from my pix 506 device Cisco has sent me a new device and I am still not able to access the msnbc website I have posted my interface below any suggestion would be appreciated. I am accessing this page fine using the device.
Result of PIX command: "sho interface"

interface ethernet0 "outside" is up, line protocol is up
Hardware is i82559 ethernet, address is 000d.2954.1d74
IP address 216.79.71.178, subnet mask 255.255.255.240
MTU 1500 bytes, BW 10000 Kbit half duplex
5058987 packets input, 3971761367 bytes, 0 no buffer
Received 568847 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
3814875 packets output, 831036840 bytes, 0 underruns
0 output errors, 8033 collisions, 0 interface resets
0 babbles, 0 late collisions, 11250 deferred
0 lost carrier, 0 no carrier
input queue (curr/max blocks): hardware (128/128) software (0/15)
output queue (curr/max blocks): hardware (0/23) software (0/9)
interface ethernet1 "inside" is up, line protocol is up
Hardware is i82559 ethernet, address is 000d.2954.1d75
IP address 192.168.1.2, subnet mask 255.255.255.0
MTU 1500 bytes, BW 10000 Kbit full duplex
4626723 packets input, 904273085 bytes, 0 no buffer
Received 681299 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
4437878 packets output, 3952764901 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 babbles, 0 late collisions, 0 deferred
0 lost carrier, 0 no carrier
input queue (curr/max blocks): hardware (128/128) software (0/35)
output queue (curr/max blocks): hardware (2/52) software (0/52)
 
can you post your config.

show config



MCSE/MCDBA
SANS GIAC + SANS FIREWALL
 
Result of PIX command: "show config"

: Saved
: Written by enable_15 at 06:16:36.787 UTC Mon Oct 27 2003
PIX Version 6.2(2)
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password XtQI.y58K7Cy522t encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname firewall
domain-name company.tac
fixup protocol ftp 21
fixup protocol http 80
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol sip 5060
fixup protocol skinny 2000
names
access-list inside_cryptomap_dyn_20 permit ip 216.79.71.176 255.255.255.240 192.168.1.240 255.255.255.240
pager lines 24
interface ethernet0 auto
interface ethernet1 auto
mtu outside 1500
mtu inside 1500
ip address outside 216.79.71.178 255.255.255.240
ip address inside 192.168.1.2 255.255.255.0
ip verify reverse-path interface outside
ip audit info action alarm
ip audit attack action alarm
pdm location 192.168.1.240 255.255.255.240 inside
pdm logging informational 100
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
route outside 0.0.0.0 0.0.0.0 216.79.71.177 1
timeout xlate 0:05:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
http server enable
http 0.0.0.0 0.0.0.0 outside
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server community company.tac
no snmp-server enable traps
tftp-server inside 192.168.1.136 /tftp-root
floodguard enable
sysopt connection permit-ipsec
no sysopt route dnat
crypto dynamic-map inside_dyn_map 20 match address inside_cryptomap_dyn_20
crypto map inside_map 65535 ipsec-isakmp dynamic inside_dyn_map
crypto map inside_map interface inside
isakmp enable inside
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 86400
vpngroup ISGroup dns-server 192.168.1.1
vpngroup ISGroup wins-server 192.168.1.10
vpngroup ISGroup default-domain TACDOM01
vpngroup ISGroup idle-time 1800
vpngroup ISGroup
telnet timeout 5
ssh timeout 5
dhcpd lease 3600
dhcpd ping_timeout 750
dhcpd auto_config outside
terminal width 80
Cryptochecksum:c3289fa69f436def8059e7bd43590367

 
access-list inside_cryptomap_dyn_20 permit ip 216.79.71.176 255.255.255.240 192.168.1.240 255.255.255.240

Doesn't this mean your vpn'n your outside network to your inside?
 
Is the DNS reply from msnbc longer than 512 bytes? If so that is your problem. The issue should be resolved in 6.2(3).
 
I am wanting to be able to access my network from an outside dialup through a ISP what would be the configuration to setup access
 
I upgraded to 6.3(3) and still not able to access MSNBC through the pix device
 
How about entering the following command:

"fixup protocol dns maximum-length 1500"


 
Tried the command and set the maximum length to 1500 but still will not access the website I have contacted cisco and they cannot figure iut this problem I changed dns servers this did not help
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top