 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Answers &#187; PIX</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/tag/pix/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers</link>
	<description></description>
	<lastBuildDate>Tue, 21 May 2013 16:56:46 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>PIX firewall internet problem</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/pix-firewall-internet-problem/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/pix-firewall-internet-problem/#comments</comments>
		<pubDate>Sat, 23 Apr 2011 07:17:32 +0000</pubDate>
		<dc:creator>Uzairahmad</dc:creator>
				<category><![CDATA[Cisco PIX Firewall]]></category>
		<category><![CDATA[Firewall configuration]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[PIX 515E]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Hello this is my pix firewall 515E configuration. Password: Type help or &#8216;?&#8217; for a list of available commands. pixfirewall&#62; en Password: pixfirewall# show runn : Saved : PIX Version 6.3(4) interface ethernet0 auto interface ethernet1 auto nameif ethernet0 outside security0 nameif ethernet1 inside security100 enable password passwd hostname pixfirewall domain-name 192.168.0.230 fixup protocol dns [...]]]></description>
				<content:encoded><![CDATA[<p>Hello<br />
this is my pix firewall 515E configuration.</p>
<p>Password:<br />
Type help or &#8216;?&#8217; for a list of available commands.<br />
pixfirewall&gt; en<br />
Password:<br />
pixfirewall# show runn<br />
: Saved<br />
:<br />
PIX Version 6.3(4)<br />
interface ethernet0 auto<br />
interface ethernet1 auto<br />
nameif ethernet0 outside security0<br />
nameif ethernet1 inside security100<br />
enable password<br />
passwd<br />
hostname pixfirewall<br />
domain-name 192.168.0.230<br />
fixup protocol dns maximum-length 512<br />
fixup protocol ftp 21<br />
fixup protocol h323 h225 1720<br />
fixup protocol h323 ras 1718-1719<br />
fixup protocol http 80<br />
fixup protocol rsh 514<br />
fixup protocol rtsp 554<br />
fixup protocol sip 5060<br />
fixup protocol sip udp 5060<br />
fixup protocol skinny 2000<br />
fixup protocol smtp 25<br />
fixup protocol sqlnet 1521<br />
fixup protocol tftp 69<br />
names<br />
name 192.168.0.144 xxx<br />
name 192.168.0.8 xxx<br />
name 192.168.0.11 xxx<br />
name 192.168.0.37 xxx<br />
name 192.168.0.41 xxx<br />
name 192.168.0.32 xxx<br />
object-group network net<br />
access-list yyyyy permit ip any host 192.168.1.2<br />
access-list yyyyy permit icmp any any<br />
access-list yyyyy permit ip any host 192.168.0.236<br />
access-list yyyyy permit ip any host 192.168.0.235<br />
access-list yyyyy permit ip any host 192.168.0.230<br />
access-list yyyyy permit ip any host 192.168.0.231<br />
access-list yyyyy permit ip any host 192.168.0.118<br />
access-list yyyyy permit ip any host 192.168.0.243<br />
access-list yyyyy permit ip any host 192.168.0.121<br />
access-list yyyyy permit ip any host 192.168.0.120<br />
access-list yyyyy permit ip any host 192.168.0.141<br />
access-list yyyyy permit ip any host 192.168.0.241<br />
access-list yyyyy permit ip any host 192.168.0.242<br />
access-list yyyyy permit ip any host 192.168.0.240<br />
access-list yyyyy permit ip any host 192.168.0.200<br />
access-list yyyyy permit ip any host 192.168.0.245<br />
access-list yyyyy permit ip any host 192.168.0.4<br />
access-list yyyyy permit ip any host 202.163.121.60<br />
access-list yyyyy permit ip any host 202.163.121.61<br />
access-list yyyyy permit ip any host 202.163.121.62<br />
access-list internet deny tcp host 192.168.0.15 any eq www<br />
access-list internet deny tcp host xxx any eq www<br />
access-list internet deny tcp host 192.168.0.26 any eq www<br />
access-list internet deny tcp host 192.168.0.27 any eq www<br />
access-list internet deny tcp host xxx any eq www<br />
access-list internet deny tcp host xxx any eq www<br />
access-list internet deny tcp host 192.168.0.43 any eq www<br />
access-list internet deny tcp host 192.168.0.44 any eq www<br />
access-list internet deny tcp host 192.168.0.47 any eq www<br />
access-list internet deny tcp host 192.168.0.48 any eq www<br />
access-list internet deny tcp host 192.168.0.49 any eq www<br />
access-list internet deny tcp host 192.168.0.50 any eq www<br />
access-list internet deny tcp host 192.168.0.52 any eq www<br />
access-list internet deny tcp host 192.168.0.53 any eq www<br />
access-list internet deny tcp host 192.168.0.54 any eq www<br />
access-list internet deny tcp host 192.168.0.55 any eq www<br />
access-list internet deny tcp host 192.168.0.56 any eq www<br />
access-list internet deny tcp host 192.168.0.57 any eq www<br />
access-list internet deny tcp host 192.168.0.58 any eq www<br />
access-list internet deny tcp host 192.168.0.72 any eq www<br />
access-list internet deny tcp host 192.168.0.75 any eq www<br />
access-list internet deny tcp host 192.168.0.76 any eq www<br />
access-list internet deny tcp host 192.168.0.77 any eq www<br />
access-list internet deny tcp host 192.168.0.78 any eq www<br />
access-list internet deny tcp host 192.168.0.80 any eq www<br />
access-list internet deny tcp host 192.168.0.81 any eq www<br />
access-list internet deny tcp host 192.168.0.84 any eq www<br />
access-list internet deny tcp host 192.168.0.85 any eq www<br />
access-list internet deny tcp host 192.168.0.86 any eq www<br />
access-list internet deny tcp host 192.168.0.87 any eq www<br />
access-list internet deny tcp host 192.168.0.88 any eq www<br />
access-list internet deny tcp host 192.168.0.46 any eq www<br />
access-list internet deny tcp host 192.168.0.98 any eq www<br />
access-list internet deny tcp host 192.168.0.74 any eq www<br />
access-list internet deny tcp host 192.168.0.21 any eq www<br />
access-list internet deny tcp host 192.168.0.23 any eq www<br />
access-list internet deny tcp host 192.168.0.99 any eq www<br />
access-list internet deny tcp host 192.168.0.100 any eq www<br />
access-list internet deny tcp host 192.168.0.102 any eq www<br />
access-list internet deny tcp host 192.168.0.104 any eq www<br />
access-list internet deny tcp host 192.168.0.133 any eq www<br />
access-list internet deny tcp host 192.168.0.134 any eq www<br />
access-list internet deny tcp host 192.168.0.129 any eq www<br />
access-list internet deny tcp host 192.168.0.132 any eq www<br />
access-list internet deny tcp host 192.168.0.153 any eq www<br />
access-list internet deny tcp host 192.168.0.154 any eq www<br />
access-list internet deny tcp host 192.168.0.105 any eq www<br />
access-list internet deny tcp host 192.168.0.59 any eq www<br />
access-list internet deny tcp host 192.168.0.60 any eq www<br />
access-list internet deny tcp host xxx any eq www<br />
access-list internet deny tcp host xxx any eq www<br />
access-list internet deny tcp host 192.168.0.12 any eq www<br />
access-list internet deny tcp host 192.168.0.17 any eq www<br />
access-list internet deny tcp host 192.168.0.24 any eq www<br />
access-list internet deny tcp host 192.168.0.63 any eq www<br />
access-list internet deny tcp host 192.168.0.65 any eq www<br />
access-list internet deny tcp host 192.168.0.66 any eq www<br />
access-list internet deny tcp host 192.168.0.67 any eq www<br />
access-list internet deny tcp host 192.168.0.70 any eq www<br />
access-list internet deny tcp host 192.168.0.90 any eq www<br />
access-list internet deny tcp host 192.168.0.64 any eq www<br />
access-list internet deny tcp host 192.168.0.94 any eq www<br />
access-list internet deny tcp host 192.168.0.19 any eq www<br />
access-list internet deny tcp host 192.168.0.170 any eq www<br />
access-list internet deny tcp host 192.168.0.148 any eq www<br />
access-list internet deny tcp host 192.168.0.183 any eq www<br />
access-list internet deny tcp host 192.168.0.181 any eq www<br />
access-list internet deny tcp host 192.168.0.182 any eq www<br />
access-list internet deny tcp host 192.168.0.184 any eq www<br />
access-list internet deny tcp host 192.168.0.185 any eq www<br />
access-list internet deny tcp host 192.168.0.186 any eq www<br />
access-list internet deny tcp host 192.168.0.187 any eq www<br />
access-list internet deny tcp host 192.168.0.188 any eq www<br />
access-list internet deny tcp host 192.168.0.189 any eq www<br />
access-list internet deny tcp host 192.168.0.190 any eq www<br />
access-list internet deny tcp host 192.168.0.191 any eq www<br />
access-list internet deny tcp host 192.168.0.192 any eq www<br />
access-list internet deny tcp host 192.168.0.193 any eq www<br />
access-list internet deny tcp host 192.168.0.194 any eq www<br />
access-list internet deny tcp host 192.168.0.195 any eq www<br />
access-list internet deny tcp host 192.168.0.196 any eq www<br />
access-list internet deny tcp host 192.168.0.197 any eq www<br />
access-list internet deny tcp host 192.168.0.198 any eq www<br />
access-list internet deny tcp host 192.168.0.199 any eq www<br />
access-list internet deny tcp host 192.168.0.29 any eq www<br />
access-list internet deny tcp host 192.168.0.30 any eq www<br />
access-list internet deny tcp host 192.168.0.35 any eq www<br />
access-list internet deny tcp host 192.168.0.36 any eq www<br />
access-list internet permit ip any any<br />
access-list 111 permit ip 192.168.0.0 255.255.255.0 host 172.16.0.11<br />
access-list 111 permit ip 192.168.0.0 255.255.255.0 host 172.16.0.12<br />
access-list 111 permit ip 192.168.0.0 255.255.255.0 host 172.16.0.13<br />
access-list 111 permit ip 192.168.0.0 255.255.255.0 host 172.16.0.14<br />
access-list 111 permit ip 192.168.0.0 255.255.255.0 host 172.16.0.15<br />
access-list 111 permit ip 192.168.0.0 255.255.255.0 host 172.16.0.16<br />
access-list 111 permit ip 192.168.0.0 255.255.255.0 host 172.16.0.17<br />
access-list 111 permit ip 192.168.0.0 255.255.255.0 host 172.16.0.18<br />
access-list 111 permit ip 192.168.0.0 255.255.255.0 host 172.16.0.19<br />
access-list 111 permit ip 192.168.0.0 255.255.255.0 host 172.16.0.20<br />
pager lines 24<br />
mtu outside 1500<br />
mtu inside 1500<br />
ip address outside (Public IP) 255.255.255.248<br />
ip address inside 192.168.0.250 255.255.255.0<br />
ip audit info action alarm<br />
ip audit attack action alarm<br />
no failover<br />
failover timeout 0:00:00<br />
failover poll 15<br />
no failover ip address outside<br />
no failover ip address inside<br />
pdm logging informational 100<br />
pdm history enable<br />
arp timeout 14400<br />
global (outside) 111 192.168.0.248<br />
global (outside) 1 (PublicIP)<br />
nat (inside) 0 access-list 111<br />
nat (inside) 1 0.0.0.0 0.0.0.0 0 0<br />
static (inside,outside) 192.168.0.230 192.168.0.230 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.231 192.168.0.231 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.236 192.168.0.236 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.235 192.168.0.235 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.243 192.168.0.243 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.121 192.168.0.121 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.240 192.168.0.240 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.200 192.168.0.200 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.245 192.168.0.245 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.4 192.168.0.4 netmask 255.255.255.255 0 0<br />
static (inside,outside) 202.163.121.60 192.168.0.4 netmask 255.255.255.255 0 0<br />
static (inside,outside) 202.163.121.61 192.168.0.232 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.242 192.168.0.242 netmask 255.255.255.255 0 0<br />
static (inside,outside) 192.168.0.241 192.168.0.241 netmask 255.255.255.255 0 0<br />
access-group yyyyy in interface outside<br />
access-group internet in interface inside<br />
conduit permit icmp any any<br />
route outside 0.0.0.0 0.0.0.0 Router Interface Public IP 1<br />
timeout xlate 3:00:00<br />
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00<br />
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00<br />
timeout uauth 0:05:00 absolute<br />
aaa-server TACACS+ protocol tacacs+<br />
aaa-server TACACS+ max-failed-attempts 3<br />
aaa-server TACACS+ deadtime 10<br />
aaa-server RADIUS protocol radius<br />
aaa-server RADIUS max-failed-attempts 3<br />
aaa-server RADIUS deadtime 10<br />
aaa-server LOCAL protocol local<br />
http server enable<br />
http 192.168.0.0 255.255.255.0 inside<br />
no snmp-server location<br />
no snmp-server contact<br />
snmp-server community public<br />
no snmp-server enable traps<br />
tftp-server inside xxxx tftp-root<br />
floodguard enable<br />
telnet (Public IP) 255.255.255.248 outside<br />
telnet 192.168.0.0 255.255.255.0 inside<br />
telnet (Router Interface IP) 255.255.255.255 inside<br />
telnet timeout 5<br />
ssh timeout 5<br />
console timeout 0<br />
pixfirewall#<br />
pixfirewall#<br />
pixfirewall#<br />
pixfirewall#<br />
pixfirewall#</p>
<p>My question is&#8230;&#8230;.<br />
i want to allow internet on this IP 192.168.0.231<br />
How can i do so????<br />
i have done this<br />
 no access-list yyyyy permit ip any host 192.168.0.231<br />
and<br />
no static (inside,outside) 192.168.0.231 192.168.0.231 netmask 255.255.255.255 0 0<br />
but in vain<br />
Please help me</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/pix-firewall-internet-problem/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Deploying VOIP and QOS</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/deploying-voip-and-qos/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/deploying-voip-and-qos/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 15:25:24 +0000</pubDate>
		<dc:creator>Karl Gechlik</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Cisco Routers]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[HP switches]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[QoS]]></category>
		<category><![CDATA[VoIP]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[We want to deploy VOIP to our network. We first need to implement QOS how can we do that? We have all HP switches and Cisco routers. The firewall is also a Cisco (PIX).]]></description>
				<content:encoded><![CDATA[<p>We<br />
     want to deploy VOIP to our network. We first need to implement QOS how can<br />
     we do that? We have all HP switches and Cisco routers. The firewall is<br />
     also a Cisco (PIX).</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/deploying-voip-and-qos/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Which tool is used to configure 50 pix firewall?</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/whict-tool-is-use-to-configure-50-pix-firewall/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/whict-tool-is-use-to-configure-50-pix-firewall/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 05:02:32 +0000</pubDate>
		<dc:creator>Cybersoni</dc:creator>
				<category><![CDATA[Cisco PIX 515E]]></category>
		<category><![CDATA[Cisco PIX Firewall]]></category>
		<category><![CDATA[Firewall configuration]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[PIX]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[i have 50 pix firewall and how will i configure these firewall.]]></description>
				<content:encoded><![CDATA[<p>i have 50 pix firewall and how will i configure these firewall.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/whict-tool-is-use-to-configure-50-pix-firewall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting up PIX535 but no network connection at all</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/setting-up-pix535-but-no-network-connection-at-all/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/setting-up-pix535-but-no-network-connection-at-all/#comments</comments>
		<pubDate>Wed, 19 May 2010 19:18:52 +0000</pubDate>
		<dc:creator>springman</dc:creator>
				<category><![CDATA[Cisco PIX]]></category>
		<category><![CDATA[Firewall management]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[PIX 535]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I am setting up spare firewall on an old PIX 535. I reset the box to factory default, assign the inside interfact an IP address and use a cross-over cable to for a laptop to connet to PIX.  The problem is I am not able to ping the firewall from the laptop vise versa.  There is [...]]]></description>
				<content:encoded><![CDATA[<p>I am setting up spare firewall on an old PIX 535. I reset the box to factory default, assign the inside interfact an IP address and use a cross-over cable to for a laptop to connet to PIX.  The problem is I am not able to ping the firewall from the laptop vise versa.  There is no any ACL on the PIX.  What could go wrong? <br/><br/> The PIX is now on 6.3(3). I hate the old IOS.  I am trying to update it to 8.0 but the first thing I need to have is a network access. The inferface is not shutdown and it has an IP address assigned. What could possibly cause the default setting without network access?  <br/><br/></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/setting-up-pix535-but-no-network-connection-at-all/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Combining Networks with Same IP Scheme, VLAN,</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/combining-networks-with-same-ip-scheme-vlan/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/combining-networks-with-same-ip-scheme-vlan/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 16:12:07 +0000</pubDate>
		<dc:creator>Ramii</dc:creator>
				<category><![CDATA[ASA]]></category>
		<category><![CDATA[Cisco 3550]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[Network Configuration]]></category>
		<category><![CDATA[Network management]]></category>
		<category><![CDATA[Network Topology]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[PIX 506e]]></category>
		<category><![CDATA[PIX 515E]]></category>
		<category><![CDATA[VLAN]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[WAN]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Hi, We are combining an couple offices next week &#038; i need some advice. The networks already have VLANs set up. we have a Cisco 3550 Layer 3 switch set up to route traffic. The servers are on this site also. The network IP&#8217;s are 10.1.1.x, 10.1.4.x &#038; 10.1.5.x. Servers reside on all of those [...]]]></description>
				<content:encoded><![CDATA[<p>Hi, We are combining an couple offices next week &#038; i need some advice. The networks already have VLANs set up. we have a Cisco 3550 Layer 3 switch set up to route traffic. The servers are on this site also. The network IP&#8217;s are 10.1.1.x, 10.1.4.x &#038; 10.1.5.x. Servers reside on all of those networks. The network they are moving to is on a 10.1.3.x network. We have a Cisco PIX 506e &#038; 515 set up to do VPN between the 10.1.1.x &#038; 10.1.3.x networks. I have ordered another smart switch to put on the 10.1.3.x network so i can create the same VLANs on that network. (10.1.4.x &#038; 10.1.5.x.) Am i thinking right that i need to do this, or should i be going a different route to set up the networks &#038; route traffice the way i need to? I really want to keep the IP Scheme that everyone is already on, but if this cannot be done, i can do something else. I did read one situation from http://itknowledgeexchange.techtarget.com/itanswers/site-to-site-problems/ but this setup is almost the same as mine without the VLANs. Any assistance is greatly appreciated.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/combining-networks-with-same-ip-scheme-vlan/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cisco ASA 5510 site-to-site with PIX v6.3</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/asa-5510-site-to-site-with-pix-v63/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/asa-5510-site-to-site-with-pix-v63/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 19:29:09 +0000</pubDate>
		<dc:creator>Madpawn</dc:creator>
				<category><![CDATA[ASA]]></category>
		<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[Cisco ASA 5510]]></category>
		<category><![CDATA[Cisco PIX]]></category>
		<category><![CDATA[DMZ]]></category>
		<category><![CDATA[IPsec]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[PIX 6.3]]></category>
		<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I&#8217;ve recently developed a need to connect 2 networks together. One network (PIX Network) is currently connected to another network (DOMAIN 1) already via IPSEC site-to-site VPN. The other (ASA) is connected to many other sites via IPSEC site-to-site VPN and is those sites main domain server (DNS, DHCP, File, ext&#8230;) PIX site is not [...]]]></description>
				<content:encoded><![CDATA[<p>I&#8217;ve recently developed a need to connect 2 networks together. One network (PIX Network) is currently connected to another network (DOMAIN 1) already via IPSEC site-to-site VPN. The other (ASA) is connected to many other sites via IPSEC site-to-site VPN and is those sites main domain server (DNS, DHCP, File, ext&#8230;) </p>
<p>PIX site is not a member of a domain, but uses DOMAIN 1&#8242;s file server to do work. </p>
<p>I need to connect the PIX and ASA network together by IPSEC site-to-site VPN, normally this would be a no brainier and would go down without a hitch, but there is a small problem in all of this. ASA and DOMAIN 1 have the same ip schema and the main assets PIX needs to use reside at the same ip on both networks. this is where my problem comes in. </p>
<p>PIX needs to be able to access DOMAIN 1&#8242;s file server which resides at 192.168.0.1 and ASA&#8217;s file server which also resides at 192.168.0.1 on it&#8217;s network at the same time.</p>
<p>I was thinking I could some how setup a DMZ on ASA and only allow access to the DMZ to the PIX network. this would eliminate the ip conflicts of the file servers and PIX would be able to work on both at the same time. </p>
<p>The problem is I do not know how to go about this on the ASA network. it has an ASA5510, but no DMZ is currently setup on it and I can not find in ASDM where to set it up at, nor do I know how to do it in CLI. Also is there a way for the DMZ interface to work through my external Vlan 1?</p>
<p>Once the ASA side is setup I&#8217;m unsure how to configure the PIX side of this.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/asa-5510-site-to-site-with-pix-v63/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cisco ASA5510</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/cisco-asa5510/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/cisco-asa5510/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 12:56:39 +0000</pubDate>
		<dc:creator>Kwt712</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Cisco ASA5510]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[PIX]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I need to find out if there is a command to shutdown Cisco ASA5510 firewall rather then walking up to the firewall and pulling the power plug &#8230; thanks]]></description>
				<content:encoded><![CDATA[<p>I need to find out if there is a command to shutdown Cisco ASA5510 firewall rather then walking up to the firewall and pulling the power plug &#8230; thanks</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/cisco-asa5510/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CiscoASA5505 DNS not getting to domain reverse lookup zones.</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/ciscoasa5505-dns-not-getting-to-domain-reverse-lookup-zones/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/ciscoasa5505-dns-not-getting-to-domain-reverse-lookup-zones/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 15:30:08 +0000</pubDate>
		<dc:creator>Shadowspapa</dc:creator>
				<category><![CDATA[Cisco ASA 5505]]></category>
		<category><![CDATA[DHCP]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[Reverse Lookup]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[We are a state agency with a main office here, then about 45 smaller offices throughout the state. The small 1 person offices connect back here via a web provider (ISP) and VPN client. The rest connect back here using either a Cisco PIX 501 (4 of our older small offices) or a Cisco ASA5505 [...]]]></description>
				<content:encoded><![CDATA[<p>We are a state agency with a main office here, then about 45 smaller offices throughout the state.<br />
The small 1 person offices connect back here via a web provider (ISP) and VPN client.<br />
The rest connect back here using either a Cisco PIX 501 (4 of our older small offices) or a Cisco ASA5505 &#8211; and in either case, use LAN-to-LAN connections back to an Altega concentrator. The PIX and ASA devices BOTH serve as their offices DHCP provider/server. Those offices get their IP address and DNS server and WINS server settings from the DHCP services of the PIX or concentrator.<br />
The issue:<br />
Those here locally that get their DHCP from our DCs are in the appropriate reverse lookup zones.<br />
Those that use the VPN client to connect back here get their DHCP address, etc. from the DCs here in this building as well. They are also all in the reverse lookup zones.<br />
Those that use the PIX devices to get back here show up in the reverse lookup zones!<br />
Now the kicker &#8211; those that use the ASA to get back here and get their addresses from the ASA DHCP are NOT registered in reverse lookup zones here!<br />
If the computer has a STATIC IP address and manually assigned DNS and WINS settings, it WILL register back here.<br />
So, anything that has either a STATIC assigned IP and DNS info registers, anything that gets DHCP assigned info from a server here registers, anything using the PIX for DHCP registers, but anything using an ASA AND getting a DHCP assignment from said ASA is NOT in the reverse lookup zones back here!<br />
We are ALL so confused! Our senoir staff, even the folks at ITE (IT Enterprise) who are levels way above me &#8220;don&#8217;t get it&#8221;.<br />
Ideas????<br />
Microsoft said it&#8217;s a Cisco issue, either the device or our configuration (or lack there-of) and the test they have run make me believe them. But then why does the PIX send that info back here and the ASA not? There are NO SPECIAL settings in the PX at all. In fact, the ASAs are setup almost exactly like the PIXs &#8211; we basically converted the PIX settings for the ASA.<br />
AARRG &#8211; (can I say that here?)</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/ciscoasa5505-dns-not-getting-to-domain-reverse-lookup-zones/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to locally authenticate users using PPTP on a local PIX firewall</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/how-to-locally-authenticate-users-using-pptp-on-a-local-pix-firewall/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/how-to-locally-authenticate-users-using-pptp-on-a-local-pix-firewall/#comments</comments>
		<pubDate>Thu, 12 Mar 2009 22:27:21 +0000</pubDate>
		<dc:creator>NetworkingATE</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Datacenter Server]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Network firewalls]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[Point-to-point tunneling protocol (PPTP)]]></category>
		<category><![CDATA[PPTP]]></category>
		<category><![CDATA[Tunneling]]></category>
		<category><![CDATA[Windows 2003 networking]]></category>
		<category><![CDATA[Windows Server 2003]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Question Edited by Serena3]]></description>
				<content:encoded><![CDATA[Question Edited by Serena3]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/how-to-locally-authenticate-users-using-pptp-on-a-local-pix-firewall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to block P2P applications in PIX 525 firewall</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/how-to-block-p2p-applications-in-pix-firewall-525/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/how-to-block-p2p-applications-in-pix-firewall-525/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 07:36:02 +0000</pubDate>
		<dc:creator>Yasir Irfan</dc:creator>
				<category><![CDATA[Application firewalls]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Cisco PIX]]></category>
		<category><![CDATA[Cisco PIX 525]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[P2P applications]]></category>
		<category><![CDATA[P2P blocking]]></category>
		<category><![CDATA[Peer-to-Peer file sharing]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[PIX 525]]></category>
		<category><![CDATA[PIX 525 firewall]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I need to know how to block p2p applications using a pix firewall 525]]></description>
				<content:encoded><![CDATA[<p>I need to know how to block p2p applications using a pix firewall 525</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/how-to-block-p2p-applications-in-pix-firewall-525/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/20 queries in 0.028 seconds using memcached
Object Caching 1042/1158 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-21 19:02:30 -->