Page 3 of 3 FirstFirst 123
Results 21 to 28 of 28
  1. #21

    Default Re: PIX 506e installation


    ridney, understood what u meant..but the thing is from my ISA the WiFi NIC interface cannot get any receiving activity. Even I made already frm the pix the proper subnet mask "route inside 192.168.2.0 255.255.255.0 192.168.1.2 1" as what u suggested frm ur previous post. Is there any settings that I need to set on the pix aside frm this routing? thanks

    PIX Version 6.3(5)
    interface ethernet0 auto
    interface ethernet1 auto
    nameif ethernet0 outside security0
    nameif ethernet1 inside security100
    enable password hbNy3ju8pQKZ0U57 encrypted
    passwd 2KFQnbNIdI.2KYOU encrypted
    hostname pixfirewall
    domain-name ciscopix.com
    clock timezone PKT 5
    fixup protocol dns maximum-length 512
    fixup protocol ftp 21
    fixup protocol h323 h225 1720
    fixup protocol h323 ras 1718-1719
    fixup protocol http 80
    fixup protocol rsh 514
    fixup protocol rtsp 554
    fixup protocol sip 5060
    fixup protocol sip udp 5060
    fixup protocol skinny 2000
    fixup protocol smtp 25
    fixup protocol sqlnet 1521
    fixup protocol tftp 69
    names
    access-list outside_access_in permit ip any any
    pager lines 24
    mtu outside 1500
    mtu inside 1500
    ip address outside 202.124.141.74 255.255.255.248
    ip address inside 192.168.1.1 255.255.255.0
    ip audit info action alarm
    ip audit attack action alarm
    pdm location 192.168.0.0 255.255.255.0 inside
    pdm location 192.168.1.2 255.255.255.255 inside
    pdm location 202.124.141.73 255.255.255.255 outside
    pdm location 192.168.2.0 255.255.255.0 inside
    pdm logging informational 100
    pdm history enable
    arp timeout 14400
    global (outside) 1 interface
    nat (inside) 1 0.0.0.0 0.0.0.0 0 0
    access-group outside_access_in in interface outside
    route outside 0.0.0.0 0.0.0.0 202.124.141.73 1
    route inside 192.168.0.0 255.255.255.0 192.168.1.2 1
    route inside 192.168.2.0 255.255.255.0 192.168.1.2 1
    timeout xlate 0:05:00
    timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
    timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
    timeout sip-disconnect 0:02:00 sip-invite 0:03:00
    timeout uauth 0:05:00 absolute
    aaa-server TACACS+ protocol tacacs+
    aaa-server TACACS+ max-failed-attempts 3
    aaa-server TACACS+ deadtime 10
    aaa-server RADIUS protocol radius
    aaa-server RADIUS max-failed-attempts 3
    aaa-server RADIUS deadtime 10
    aaa-server LOCAL protocol local
    http server enable
    http 192.168.1.0 255.255.255.0 inside
    no snmp-server location
    no snmp-server contact
    snmp-server community public
    no snmp-server enable traps
    floodguard enable
    telnet timeout 5
    ssh timeout 5
    console timeout 0
    vpdn username admin password *********
    vpdn enable outside
    vpdn enable inside
    dhcpd address 192.168.1.2-192.168.1.10 inside
    dhcpd lease 3600
    dhcpd ping_timeout 750
    dhcpd auto_config outside
    dhcpd enable inside
    username admin password AULMP2pyBpRZ4Zva encrypted privilege 15
    username mbvales password SHCeMeoGZJ.cTeqt encrypted privilege 15
    terminal width 80
    Cryptochecksum:13ee6d0a54f7402a6a9eba564bb10ccf
    : end

  2. #22

    Default Re: PIX 506e installation

    have you installed routes on the isa server?
    try to check connectivity from your wifi clients by pinging the following:
    a) 192.168.2.1 (gateway)
    - if you can ping the gateway then there's no problem with your wifi setup
    b) 192.168.1.2 (isa interface between pix)
    - if you can ping the other nic of your isa server then there's no problem with your isa routing packets
    c) 192.168.1.1 (pix inside interface)
    - if you can ping the pix inside interface then there's no problem with your pix routing configuration
    d) 202.124.141.73 (rcst router) (configure the pix to allow icmp echo and echo-replies on the outside interface using access-list to do this)
    - if you can ping the rcst router then everything works fine, if not then check PAT on firewall

  3. #23

    Default Re: PIX 506e installation

    Bro Ridney,Thanks a lot for your help..on last thing, how to setup on PIX to allow SSL access, via https, from static address 195.138.117.70 and how do I check/know from our local ISP that they allows encrypted traffic.

  4. #24

    Default Re: PIX 506e installation

    In addition & relation to my message above; i tried this command but still doesn't work.

    pixfirewall (config)# static (inside,outside) tcp 195.138.117.70 992 192.168.1.1 992 netmask 255.255.255.255
    pixfirewall (config)# access-list 101 permit tcp any host 195.138.117.70 eq 992
    pixfirewall (config)# access-group 101 in interface outside
    pixfirewall (config)# write mem

    Any Help? Thanks

  5. #25

    Default Re: PIX 506e installation

    hi mbvales, sorry for the late reply as I was quite busy days ago. do you want this to be an outbound service? or do you want to this to be inbound?

  6. #26

    Default Re: PIX 506e installation

    Hi Ridney, Inbound service coz' our head office want to access my PIX to setup VPN configuration and etc.

  7. #27

    Default Re: PIX 506e installation

    Can you setup your network that will allow a host on your remote site to RDP one of your host or server and telnet the pix from there?

    use the telnet command on the pix to allow what host or subnet you allow having access to the console.

    pix(config)# telnet 192.168.1.0 255.255.255.0

  8. #28

    Default Re: PIX 506e installation

    Bro, sorry for the late reply; bit busy here..anyway, I got it already on how to allow the public IP from our head office via Telnet, SSL & https. I configured it thru PDM.

    Anybody, can give me an idea on how to configure/allow pcanywhere on the PIX and how to translate my outside pix interface (real ip) to point or redirect to my Internal IP of my ISA if we use pcanywhere? Thanks in advance.

  9.    Advertisement

Page 3 of 3 FirstFirst 123

Similar Threads

 
  1. installing Xp, system halt, error occur.
    By etgo in forum Computer Hardware
    Replies: 34
    Last Post: 10-12-2010, 06:58 AM
  2. iSTORYA.net 2nd Anniversary PIX...
    By madzZz in forum Parties & Events
    Replies: 108
    Last Post: 09-15-2005, 12:25 PM
  3. Replies: 2
    Last Post: 08-03-2005, 03:30 PM
  4. WARNING: For Symbian Phones AYAW PATAKA INSTALL UG .SIS na FILE
    By ryanrocks in forum Gizmos & Gadgets (Old)
    Replies: 11
    Last Post: 08-01-2005, 09:19 PM
  5. how to install java apps/games in motorola c651
    By 8088 in forum Gizmos & Gadgets (Old)
    Replies: 4
    Last Post: 04-18-2005, 03:40 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
about us
We are the first Cebu Online Media.

iSTORYA.NET is Cebu's Biggest, Southern Philippines' Most Active, and the Philippines' Strongest Online Community!
follow us
#top