Firewall IP ranges address for C160 AS-AV... updates

Hello,
On our Cisco FW, we have opened tcp 80/443 flow for the sites shown below. We found IP adresses doing DNS Lookup. Unfortunately it seems IPs ares different dependeing the time / date we perform DNS lookup. Result, we didn't open enough, Updates are KO.
What are the IP ranges we should open on our FW?
Any other solution?
Many thanks in advance for the help
Sites List
80 HTTP Out                      downloads.ironport.com                                            Service updates, except for AsyncOS upgrades and McAfee definitions.
80 HTTP Out                      updates.ironport.com                                                 AsyncOS upgrades and McAfee Anti-Virus definitions.
443 TCP Out                       res.cisco.com                                                                   Cisco Registered Envelope Service
443 TCP Out                       updates-static.ironport.com                                     Verify the latest files for the update server.
443 TCP Out                       phonehome.senderbase.org                                   Receive/Send Virus Outbreak
MAC

KB articles #422, #994, #1020 on Ironport's support site list the required IP addresses/URLs and configuration options.
As per #422 "...downloads.ironport.com will be served via Akamai's servers. Due to the dynamic nature of this service, this means that the actual IP addresses will be changing constantly. The full URL remains: http://downloads.ironport.com/asyncos/upgrade"
If your FW policy does not allow dynamic connections, use the static IPs/hostnames in the articles. I'd add downloads-static.ironport.com/204.15.82.8 and update-manifests.ironport.com/204.15.82.17. to your list.

Similar Messages

  • Having trouble verifying my rescue email address for my daughters iPad update. Each time I put in my apple id and password it is rejected

    I Am having trouble verifying my rescue email address for my daughters iPad software update. Every time I put in my apple id and password it is rejected. I know it's right because I used it to sign in here v

    If you do not have a Rescue email (secondary email), you need to contact apple support, they will guide you through the process of resetting your security questions.
    https://ssl.apple.com/emea/support/itunes/contact.html

  • Do I need the same ip address for my computer, router and printer?

    Do I need the same IP address for my computer, router and printer?
    I am trying to reset my router. I have had a lot of problems with "no connection" to my wireless printer. I reinstalled the software and it works for a while.
    Also, lose connection a lot on my laptop or it says I am a guest. My cable provider said it is my router.

    A typical convenient-sized "block" of addresses commonly used is just under 256 addresses. The router almost always is at location xx.yy.zz.1
    By default, DHCP will pass out addresses starting at the next address, xx.yy.zz.2 and keep going up toward 254.
    By convention, the Address at the end of the range ( xx.yy.zz.255 in this case) is a "magic" address used for broadcast messages, and must not be assigned to an actual device.
    To talk to each other easily, the Addresses must "match" in the first three octets of their address, and be different in the last octet, as the above examples do.
    When you produce a reference outside that range, such as asking for Apple's web page at:
    http://17.149.160.49
    It is sent to your Router, which acts as your "agent" in dealing with the Internet. The Router hides your computer's local address and uses its own Public address (provided automatically by your ISP) so send out packets on your behalf, and listen for the answering packets coming back.
    When you use a Router that you control, your computer cannot receive unsolicited queries from the Internet at large because the Router's Firewall discards them. Having a Router that you control means you already have the protection of its Firewall, and need not enable the Firewall built-into your Mac.

  • I need help setting up my Apple wireless network so that there are no conflicts with IP addresses for any of my devices.

    I have 2 Airport Extreme Base Stations, 1 is a 5th generation 802.11n and 1 is a 2nd generation 802.11n.  I have 2 Extreme Express Base Stations which are 2nd generation 802.11a/n.  The idea is to create a network that works throughout my 2 story house and extend into the garage.  It's not a large house 1400 sq ft wood construction.  The internet feed comes into the Hughes Net modem upstairs.  This is where I want the main base station (5th generation). I eventually will connect a network drive and printer to it.  I then want to place the second base station in the room directly under the upstairs room where the main base station is and connect my desk top computer to it.  In the living room I will have one of the Express Base Stations connected to the Micro Cell and house stereo system.  In the garage (50' away from the living room Express Station & 75' from the Main Base Station) I will place the other Extreme Express Base Station to be connected to the garage stereo system.  All of this is with the idea to extend the range of my network for all my devices and airplay to my stereo systems. 
    Ok, so I have a lot of wireless devices. 2 2nd geneartion iPads, 2 iPhone 4s's, 3 Wi-Fi enabled Sony TVs, Apple TV (near the house stereo Extreme Express), AT&T Micro Cell connected to house stereo Extreme Express, Lorex Security DVR system (connected to main base station upstairs), Whole-House DTV Network system,1 Macintosh Quicksilver Desktop computer, 1 MacBook Pro, and 1 Mac AirBook.  As you can see I need a lot of DHCP IP addresses.
    So, how do I go about setting this all up?  I have read countless articles and discussions but I still have conflicts.  It usually mostly, but not limited to, effects my wife's AirBook.  Not good at all!  I used to have a WDS setup but I understand that the 802.11n Airport Extreme's do not support this.  And when I try to distribute a range of IP addresses I run into problems.  So can someone please help me resolve this headache?

    Configure the Extreme connected to the Hughes Net modem as your router. In other words in AirPort Utility, Network tab > Router Mode should be set to "DHCP and NAT". It will provide IP addresses to all the devices on your network.
    All other AirPort devices on your network should be configured as bridges: Router Mode "Off".
    You may want to configure static IP addresses for any equipment that is likely to be permanently installed. For them, there is no reason to have the Extreme issue an IP address, and they can keep the same one forever.
    The Microcell may be able to connect to the Express's LAN port such devices that have to handle voice or other real time audio or video streaming are generally best installed using a strictly wired connection. The same applies to the Sony TV and AppleTV. Keep them on a wired LAN served by the Extreme, avoiding any reliance on a wireless link if at all possible.
    The way to implement a complex network like yours is to add one device at a time. Ensure it connects reliably, then add another. You have a lot of work to do.
    WDS can be implemented even with new Extremes but its performance is likely to be so unacceptable that it would be nothing more than an exercise in frustration for you.

  • I have 2 websites and 1 IP address for my server, how do I set the DNS up?

    I am having trouble following the boards and the Server Admin instructions to make sure I can activate a website.
    IP address for the Snow Leopard Server on a mac mini
    Server Settings for Web has the 2 domain names listed pointing to the same IP address and same port 80.
    How do I point the DNS correctly to the domain I want to respond?  www.ziggythewinegal.com
    If you put the IP address in a browser, it returns the default domain which is just the apache/osx server page. 64.142.85.71
    If you put the first domain name in a browswer, it does the same. www.JoelQuigley.com
    How do I setup the DNS to www.ziggythewinegal.com which is in the folder WebServer>ziggy>index.php ?

    64.142.85.71 has an existing public DNS translation, so you'll be adding DNS CNAME (alias) records for the each of the additional hosts into your public DNS at WorldNIC DNS servers.
    Your local host either isn't running DNS, or it's running local DNS.  If it's running local DNS, then hopefully it's not running with the same domain name as your public DNS services; that you have an external DNS zone and an internal DNS zone, with an external DNS domain and an internal domain name.  If you are running DNS locally and are using the same domain name for internal and external DNS servers, then you'll also need to add the translation for the new web sites into your local DNS server configuration.
    Once the translation is added, add - as John Lockwood indicates - Sites into your web server. 
    The numbers of folders can vary.  Different sites may or may not be in the same folder, depending on what you're doing. Multiple ttraditional static HTML web sites are probably stored in separate folders.  A single site with several names can be in the same folder.  A web content management system (CMS) can be stored in one folder.
    If you have a firewall here (and you should), then you may need some additional steps.  Particularly if you're running NAT, and don't already have rules and port-forwarding enabled on the server.  Given it appears you're using mail with this server, there are likely some rules in place, though you'll need to confirm that port 80 TCP and possibly port 443 TCP are (also) being forwarded for your web services.
    Here is a write-up on adding what Apple calls Sites and what Apache calls virtual hosts.

  • How do I open ports on my airport extreme and assign a fixed IP Address for a device connected to my network?

    I recently had a security system installed in my house.  One of the features is an EPAD which enables me to have a virtual keypad on my iphone, and computer to operate the alarm system.  The technician was not familiar with Mac's and Airports.  How do I open port 80 to 80 in my airport and assign a fixed IP address for the EPAD?  Apparently this is what is needed to make this work.

    There are three ranges of "strictly local" IP addresses reserved for local Network use:
    192.168.xxx.yyy
    172.16.xxx.yyy
    10.xxx.yyy.zzz
    What your Router does for you is to act as your agent on the Internet.Your requests are packaged up and forwarded on your behalf, and only when a response is expected is the response returned to your local IP address.
    Directing Network Traffic to a Specific Computer on Your
    Network (Port Mapping)
    AirPort Extreme uses Network Address Translation (NAT) to share a single IP address with the computers that join the AirPort Extreme network. To provide Internet access to several computers with one IP address, NAT assigns private IP addresses to each computer on the AirPort Extreme network, and then matches these addresses with port numbers. The wireless device creates a port-to-private IP address table entry when a computer on your AirPort (private) network sends a request for information to the Internet.
    If you’re using a web, AppleShare, or FTP server on your AirPort Extreme network, other computers initiate communication with your server. Because the Apple wireless device has no table entries for these requests, it has no way of directing the information to the appropriate computer on your AirPort network.
    To ensure that requests are properly routed to your web, AppleShare, or FTP server, you need to establish a permanent IP address for your server and provide inbound port mapping information to your Apple wireless device.
    To set up inbound port mapping:
    1) Open AirPort Utility, select your wireless device, and then choose Base Station > Manual Setup, or double-click the device icon to open its configuration in a separate window. Enter the password if necessary.
    2) Click the Advanced button, and then click Port Mapping.
    3) Click the Add button and choose a service, such as Personal File Sharing, from the Service pop-up menu.

  • Static NAT and same IP address for two interfaces

    We have a Cisco ASA 5520 and in order to conserve public IP addresses and configuration (possibly) can we use the same public IP address for a static NAT with two different interfaces? Here is an example of what I'm refering too where 10.10.10.10 would be the same public IP address.
    static (inside,Outside) 10.10.10.10  access-list inside_nat_static_1
    static (production,Outside) 10.10.10.10  access-list production_nat_static_1
    Thanks for any help.
    Jeff

    Hi Jeff,
    Unfortunately this cannot be done, on the ASA packet classification is done on the basis of mac-address, destination nat and route, and here you are confusing the firewall, to which interface does the ip belong to. I haven't ever tried to do it, but it should cause you issues.
    Thanks,
    Varun Rao
    Security Team,
    Cisco TAC

  • How do I find the Mac address for my 8900?

    I have a wireless network and can't connect to it at all. I have looked and typed in Blackberries search engine and came up with nothing, only answers are about a MAC computer, not what I am looking for.
    I have to add the Mac address to the wireless network in order to get past the firewall and this is not working for me, any ideas.
    Thank you,
    Animal
    Raising teenagers is like trying to nail
    jell-O to a tree!

    Found it,
    Overview
    To find the Media Access Control (MAC) address of a Wi-Fi® enabled BlackBerry smartphone, complete the following steps:
    Click Options.
    Click Status.
    The WLAN MAC field displays the MAC address for the BlackBerry smartphone.
    Raising teenagers is like trying to nail
    jell-O to a tree!

  • ASA 5520 : IP address for CSC SSM

    Hi All,
    I have an ASA 5520 with CSC SSM. I have base and plus license and want to activate it. T he IP address and gateway have to be configured on the CSC SSM. I have configured IP addresses for the INSIDE,OUTSIDE,DMZ and MGMT. The outside is a public IP address. Now for the CSC SSM what range should i give?
    There is an ISA server on the DMZ where all user IP's get PATed and on ASA this gets NATed on the ASA. Direct access to the internet exists for the servers (bypassing proxy).
    My basic doubt is about the IP address and gateway that the CSC SSM should have and is it related ot the management interface ip address?
    Thanks and Regards.
    Sonu

    Hi
    put your CSC ip address as outside interface subnet.because CSC needs automatic updates from internet.and you can able to manage CSC from remote itself.
    for EX
    your outside ip is 10.0.0.1/24,make CSC IP As 10.0.0.2/24,Gateway 10.0.0.1
    Hopes this helps
    regs
    S.Mohana sundaram

  • Public ip address for asa

    HI.......
    We have Cisco router 2851 and asa firewall. We configured on he router for IP phones and ISP connected. The ISP directly connected on the router and asa firewall connected to the router. We have plan to configure VPN on the router. We have available public ip address. if i configure the VPN on the firewall we need to configure firewall local ip address to public ip address. SO how to configure firewall local ip to public ip ? Where we can configure , mean on the router or firewall. please see my firewall and router configuration ...
    Please help .....

    The ASA would typically be where you setup your public IP Address(es). The firewall normally needs to have a public IP on the outside interface for that to work. Once it does, you can perform dynamic NAT for outbound connections ("global (Outside) 1 xxx.xxx.xxx.185 netmask 255.255.255.255" does this).
    However on the config you attached your outside interface has a private (RFC 1918) address:
    interface Ethernet0/3
    speed 100
    duplex full
    nameif Outside
    security-level 0
    ip address 192.168.255.2 255.255.255.252
    Plus it being a /30 only gives you two addresses - one for the ASA and one for the router's Gi0/0 (per that config which you also attached). This is a bit odd setup but it seems to have been hacked together to work using the routing statement on the router "ip route xxx.xxx.xxx.184 255.255.255.248 192.168.255.2".
    It's really a bit of a mess and extending it further may be possible but will make it even more complicated. I'd advise having someone sit down and re-work how the public IPs are routed to make it look like a more typical setup.

  • Airport utility 6.1 change ip address for router

    Hi there,
    I want to change the IP address for the router from 192.... to 10.....?  It doesn't seem possible with the new version of the aiport utility.
    Any help would be greatly appreciated.

    You can change the IP address range that the AirPort Extreme provides as follows:
    Open Macintosh HD > Applications > Utilities > AirPort Utility
    Click directly on the AirPort Exteme icon
    Click Edit in the next small window that appears
    Click Network at the top of the next window
    Click Network Options at the bottom of the window
    Here, you can changet the iPv4 IP address range from 192.168.x.x to 10.0.x.x
    Click Save and then click Update to restart the AirPort Extreme
    IF....the Network Options button is grayed out, this indicates that the AirPort Extreme is in Bridge Mode. In that type of setup, you have another modem/router or gateway "upstream" on your network.  That is is the device that is providing the 192.168.x.x. IP addresses.
    The AirPort Exteme simply passes through that network information to connected devices in Bridge Mode, since you only want one router on the network providing IP addresses.
    You will need to check with the support folks for your modem/router or gateway if you want to modify the settings on that device.

  • Unable to set the ip address for hosted network client after creating WIFI hotspot

    Original Title: INTERNET CONNECTIVITY PROBLEM WITH MY LAPTOP WIFI HOTSPOT
    HI all
    I am able to use internet connection from my lap hotspot, when the internet source is Public or private wifi.
    so I know the cmd window commands for hotspot and settings of client(sharing to hosted network client, assigning IP address etc.,)
    but the problem I am facing is slight different
    I am using my cdma wireless broadband datacard as my source internet connection(Reliance netconnect +)
    when I try to create hotspot for this, as usual I am able to create the hotspot and able to share the internet to hostednework client.
    but I am unable to set the ip address for hosted network client, if I try to set ip 192.169.137.1 and 255.255.255.0
    as soon as I close the window, the ip address also disappears
    when connect my android phone to that hotspot, it is able to connect but there is no internet connectivity.
    when I check the hostednetwork client for packet transmission, both sent and received packet is happening., I mean transmitting
    so what cause the failure in internet connectivity but success in hotspot connectivity?
    check the screen shots...
    can u help me..
    its little complicated

    Hi,
    Please make sure the Ad hoc connection IP adress is at the same range with your local connection. In addition, how about recreate the ad hoc connection for test, please have a try.
    If problem persists, please use Network troubleshooter in Action Center to fix this problem for test.
    Roger Lu
    TechNet Community Support

  • [nQSError: 77030] Oracle BI Presentation Server Connection Error: Unable to resolve the address for cn.

    Hi Experts,
    When I use Agent functionality to send email in BIEE 11.1.1.7.0, it will generate the following error message as below:  Are you facing the same problem ? Please help me,Thanks very much.
    Global Error: [nQSError: 77030] Oracle BI Presentation Server Connection Error: Unable to resolve the address for cn.
    Error Codes: AXSBMN8D:
    The operation completed successfully.

    Can you try doing telnet to SMTP server from where BI server is installed and let us know the outcome.Just want to check if any firewall is blocking
    telnet hostname portnumber
    Thanks,

  • How to set FROM ADDRESS for EMAIL activity in Process Flow

    Hi all,
    Can any one tell how to set(which address) FROM ADDRESS for EMAIL activity in Process Flow?
    Thanks,
    Suvvi

    Did you set what OWB guide says:
    To execute a process flow with an email activity, you may need to access different host machines and ports. New security measures implemented in Oracle Database 11g Release 1 restrict access to hosts and ports. You must explicitly grant access to hosts and ports that the email activity accesses using the DBMS_NETWORK_ACL_ADMIN package.
    For example, the user OWBSYS needs to send an email through the mail server mail.example.com using port 25. The DBA must perform the following steps:
    1. Create an Access Control List (ACL) for the user OWBSYS using the following command:
    EXECUTE DBMS_NETWORK_ACL_ADMIN.CREATE_ACL
    (’acl_for_owb_cc.xml’,’ACL for Control Center’,’OWBSYS’,’CONNECT’);
    The ACL has no access control effect unless it is assigned to network target.
    2. Assign the Access Control List (ACL) to a network host, and optionally specify a TCP port range. Use the following command:
    EXECUTE DBMS_NETWORK_ACL_ADMIN.ASSIGN_ACL (’acl_for_owb_cc.xml’,’mail.example.com’,25)
    3. Commit the changes made using the COMMIT command.

  • How do I find dns address for a hp wireless printer software installation?

    Tried to enter address for wireless modem, no go.  Tried to enter address for HP printer, no go.  what do I try next?

    Hello, Router IP should be the DNS to use, but did you set the IP on the Printer to the same IP range as the Router uses?
    http://www.hp.com/global/us/en/wireless/faq.html

Maybe you are looking for

  • Lock a PDF file when converted from Smartform

    Hello Experts, In our current project we have an urgent requirement to apply a Lock to a PDF document so it cannot be amended. This is a PDF document and not an Adobe interactive form, which currently cannot be used on the project. We are seeking hel

  • Can we configure EAS and Shared services wih out a Database

    Hi All, Can any one please let me know if we can configure Essbase administration servies ans Shared services with out giving Database details while configuring. If Database schema is not yet ready to use, is it possible to configure EAS and login to

  • LiveCycle Upgrade from 7.2.2 to ES2

    Dear all, I am migrating my LiveCycle application from 7.2.2 to Livecycle ES2, as per the recommendations from Adobe the best way is to first migrate to LiveCycle ES and then to ES2. Is it possible to migrate directly to ES2, since it a very small ap

  • Replacement of true type fonts on Linux

    I have developed a report with Reports 6i on a Windows NT client using the font "Times New Roman". When I generate the report on a Linux (Suse 7.2) to a PDF-file then the font is replaced by the font "itc avant garde gothic" although I can select the

  • Disable the pop of the volume control in bootcamp XP

    How do I mute the pop when adjusting volume with iMac Keyboard in bootcamp windows XP? I turned it off in Mac Mode but can't find settings or anything with google.