I’m able to ping or ftp any other external IP. But when I try to ping or ftp my web server external (x.x.x.125) IP I can’t. However, people on the outside can ping or ftp my web server external IP.
PIX Version 6.1(4)
nameif ethernet0 outside security0
nameif ethernet1 inside security100
fixup protocol ftp 21
fixup protocol http 80
fixup protocol h323 1720
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol sip 5060
fixup protocol skinny 2000
names
access-list outside_access_in permit tcp any host x.x.x.125 eq ftp
access-list outside_access_in permit tcp any host x.x.x.125 eq ftp-data
access-list outside_access_in permit icmp any host x.x.x.125
access-list outside_access_in permit tcp any host x.x.x.125 eq www
access-list outside_access_in permit tcp any host x.x.x.125 eq 444
access-list outside_access_in permit icmp any any
access-list inside_access_in permit ip any any
access-list inside_access_in permit icmp any any
interface ethernet0 auto
interface ethernet1 auto
mtu outside 1500
mtu inside 1500
ip address outside x.x.x.122 255.255.255.248
ip address inside 192.168.0.215 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
arp timeout 14400
global (outside) 1 x.x.x.123
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) x.x.x.125 192.168.0.240 netmask 255.255.255.255 0 0
access-group outside_access_in in interface outside
access-group inside_access_in in interface inside
route outside 0.0.0.0 0.0.0.0 x.x.x.121 1
PIX Version 6.1(4)
nameif ethernet0 outside security0
nameif ethernet1 inside security100
fixup protocol ftp 21
fixup protocol http 80
fixup protocol h323 1720
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol sip 5060
fixup protocol skinny 2000
names
access-list outside_access_in permit tcp any host x.x.x.125 eq ftp
access-list outside_access_in permit tcp any host x.x.x.125 eq ftp-data
access-list outside_access_in permit icmp any host x.x.x.125
access-list outside_access_in permit tcp any host x.x.x.125 eq www
access-list outside_access_in permit tcp any host x.x.x.125 eq 444
access-list outside_access_in permit icmp any any
access-list inside_access_in permit ip any any
access-list inside_access_in permit icmp any any
interface ethernet0 auto
interface ethernet1 auto
mtu outside 1500
mtu inside 1500
ip address outside x.x.x.122 255.255.255.248
ip address inside 192.168.0.215 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
arp timeout 14400
global (outside) 1 x.x.x.123
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) x.x.x.125 192.168.0.240 netmask 255.255.255.255 0 0
access-group outside_access_in in interface outside
access-group inside_access_in in interface inside
route outside 0.0.0.0 0.0.0.0 x.x.x.121 1