Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

port redirection doesn't work

Status
Not open for further replies.

stevenriz

IS-IT--Management
May 21, 2001
1,069
0
0
I have three machines that I wish to do port redirection to. I got two to work, the other one doesn't for some reason. I can't figure it out.... Here are the commands I use.... Hopefully it is enough info for you. I don't know what I could be doing wrong. Help if you can!! Thank you very much!!
Steve


WORKS
static (corp,outside) tcp public.ip1 8080 netmask 255.255.255.255 0 0

WORKS
static (inside,outside) tcp public.ip2 8080 netmask 255.255.255.255 0 0

DOESN'T WORK
static (corp,outside) tcp public.ip3 8080 netmask 255.255.255.255 0 0

CONDUITS
conduit permit tcp host 66.238.208.103 eq conduit permit tcp host 66.238.208.102 eq conduit permit tcp host 66.238.208.106 eq
 
Update....

I added the line for the heck of it to see what happens....
conduit permit tcp host 66.238.208.106 eq 8080 any

Now it flows through as long as you put :8080 in the web address. Don'tunderstand why that works and
Steve
 
Well, I use the conduit command to allow through. With the static command I redirect anything coming in at to 8080 internally. I do have a small access list. So eliminating coduits and enhancing an access list is better?

Anyway, I rewrote the line to stop the redirect and to open up 8080 only in a new conduit line. It is working.... If we ever to to PROD (80) with this, I will have to rework the command.

Thanks all
Steve
 
HI.

> With the static command I redirect anything coming in at to 8080 internally
You're right - I missed that.

> So eliminating coduits and enhancing an access list is better
Mixing conduit and access-list is not good, so you should better use one or the other but not both.
The mix can cause such problems you have because access-list can override conduits.
The conduit command is for backward compatiblity (when you upgrade pix OS with old config).


Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top