Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

strange outbound

Status
Not open for further replies.

Guest_imported

New member
Jan 1, 1970
0
hi,
I know that's a forum for router , but I want to get help about the pix firewall.

I want to prevent some users in the inside to access the web-server on the DMZ with address exp : 192.168.0.2(of the server)

so I use outbound command like this

outbound 1 deny 192.168.0.2 255.255.255.0 80 tcp
apply (inside)1 outgoing_dest.

but the strange problem is that I got after that any access (in the inside) for the other server in the DMZ like the DNS FTP with those addresses 192.168.0.3 192.168.0.4.


what is the prb?
 
Your outbound access-list should have a mask of 255.255.255.255. The way you have it, it is denying the entire class C network of 192.168.0.0.

Hope this helps,
Paul
 
hi paul,

I'm so glad to you, yes it's mork perfectly
I suppose that working more than 15 hours a day, make me blind.

thank you again if you want some help about cisco routers or firewall let me know.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top