XPunlimited connection through Pix 506e

I have a Pix506e that I need to open port 3389 for remote connection to a Win2003 server that is running XPunlimited for 2003 Servers. I have searched the internet and have tried numerous different access list commands to try and make this work. What I'm looking for is a CCNE that can help me get this going and maybe look at my existing configuration file to tell me what isn't set up properly.

You bet....here it is
PIX Version 6.3(1)
interface ethernet0 auto
interface ethernet1 auto
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password wVolyRqUC55O9Zpf encrypted
passwd wVolyRqUC55O9Zpf encrypted
hostname TOS
domain-name
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
names
access-list nat0 permit ip 172.20.10.0 255.255.255.0 172.20.11.0 255.255.255.0
access-list acl-out permit tcp any interface outside eq pcanywhere-data
access-list acl-out permit udp any interface outside eq pcanywhere-status
access-list acl-out permit tcp any host eq pcanywhere-data
access-list acl_out permit udp any host eq 5631
access-list acl_out permit tcp any host eq pcanywhere-data
access-list acl_out permit udp any host eq pcanywhere-status
access-list acl_out permit tcp any host eq 3389
access-list acl_out permit udp any host eq 3389
pager lines 24
mtu outside 1500
mtu inside 1500
ip address outside dhcp setroute
ip address inside 172.20.10.1 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
ip local pool vpnpool 172.20.11.1-172.20.11.10
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 0 access-list nat0
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) tcp interface pcanywhere-data 172.20.10.51 pcanywhere-da
ta netmask 255.255.255.255 0 0
static (inside,outside) udp interface pcanywhere-status 172.20.10.51 pcanywhere-
status netmask 255.255.255.255 0 0
access-group acl-out in interface outside
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
sysopt connection permit-ipsec
crypto ipsec transform-set vpn1 esp-des esp-md5-hmac
crypto dynamic-map dynmap 1 set transform-set vpn1
crypto map seabrook 1 ipsec-isakmp dynamic dynmap
crypto map seabrook interface outside
isakmp enable outside
isakmp nat-traversal 20
isakmp policy 1 authentication pre-share
isakmp policy 1 encryption des
isakmp policy 1 hash md5
isakmp policy 1 group 2
isakmp policy 1 lifetime 1000
vpngroup sclient address-pool vpnpool
vpngroup sclient split-tunnel nat0
vpngroup sclient idle-time 1000
vpngroup sclient password ********
telnet 172.20.10.0 255.255.255.0 inside
telnet timeout 5
ssh 24.61.165.168 255.255.255.248 outside
ssh timeout 5
console timeout 0
dhcpd auto_config outside
terminal width 80

Similar Messages

  • SIP connection Through PIX

    Hi ,
    i have a CISCO PIX Firewall running version Version 7.2(4)......
    i want to know how many connection of SIP can be handled by PIX firewall. what is the default limit.
    Actually we have a two setup of sip , one with Juniper firewall and one with pix different location. earlier i was facing issue with juniper that the Dialer not able to send call to user,
    during troubleshooting i found that in Juniper there is ALG which have sip enabled with 64 maximum limit.. so i diabled and all calls working fine.
    Now the question is voice vendor telling me the the same issue facing by user behind PIX Firewall.

    Hi ,
    i have a CISCO PIX Firewall running version Version 7.2(4)......
    i want to know how many connection of SIP can be handled by PIX firewall. what is the default limit.
    Actually we have a two setup of sip , one with Juniper firewall and one with pix different location. earlier i was facing issue with juniper that the Dialer not able to send call to user,
    during troubleshooting i found that in Juniper there is ALG which have sip enabled with 64 maximum limit.. so i diabled and all calls working fine.
    Now the question is voice vendor telling me the the same issue facing by user behind PIX Firewall.

  • Linksys WRT600N vs CISCO PIX 506E.... Firewall / Routing Performance

    Hi:
    I am new to the forum and was hoping to tap into some of your expertise. I have a Linksys WRT600N version 1.1 and I recently acquired a CISCO PIX 506E firewall. My question is what should I use as a firewall? Both have SPI etc. Should I:
    a) Use the 506E as a firewall and use the 600 as a wireless access point, or
    b) Use the 600 as a firewall and wireless access point.
    Do both routers have the same firewall routing performance? I want to use the storage feautre on the 600N, but if I do that and use it as a wireless access point the 600 can't get the proper time from the Internet, so my time for newly created folders and files shows they are 10 years old.
    Anyway, just thought I would post and find out what some of the experts thought and maybe someone from Linksys or CISCO. I know the 506E is discontinued and was manufactured around 2001 and the 600N is a new model.
    (Edited subject to keep threads from stretching. Thanks!)
    Message Edited by JOHNDOE_06 on 05-06-2008 10:41 AM

    The PIX is a real firewall. The WRT has a firewall which mostly protects the router itself. People prefer to buy a "SPI firewall router" instead of a simple "router" even though the router firewall does nothing or little to protect the LAN. The only firewall configurations on the WRTs you can usually do is on the Access Restrictions tab. But that's usually all. The LAN itself is not protected by the firewall. You would notice this if you had a public IP subnet and ran it through the WRT: the LAN would be fully exposed to the internet. Some routers have a few functions like protection against denial of service attacks or similar. But even then this often filters only the traffic targeted at the router and not the LAN.
    The common protection of your LAN you have on the WRT is because you use private IP addresses inside your LAN and the router does NAT. However, NAT is not a security mechanism but a mechanism to solve the problem that you can only have a single public IP address but want to use multiple computers, which is why you have to use private IP addresses. Current NAT implementations usually drop unsolicited incoming traffic because they don't know to which IP address in the LAN to send it to. But the notion of NAT is to deliver and to allow connectivity. This has nothing to do with security or a firewall.
    Thus, if you want to use a real firewall use the PIX. On the PIX you can configure the traffic which is allowed to enter the LAN and which not. It is far superior in this respect to the WRT. However, as it is a older model, I cannot tell how fast the PIX is. You should be able to find the old data sheets of the PIX somewhere on the cisco website. They should mention the possible throughput. I guess it won't be an issue.
    To me another point for the PIX are the VPN capabilities which allow you to securely access your LAN while you are on the road.
    Of course, you must know how to configure the PIX correctly. It is a complex device and can be configured pretty much for anything you like. This means of course if you do it wrong you may end up with little or no security.
    BTW, there are no people from linksys in this forums except the moderators (which may be from lithium). To hear from Linksys you have to contact Linksys support.

  • Pix 506e firewall configring for mail( Exhange), Web, FTP server

    Hi
    I am Hemant, We have pix 506e firewall, D-link ADSL dsl-502t and my IBM xseries 236 server.
    I have fix static live ip 59.181.103.220 which i have got ISP (MTNL), and the same ip is given in fqdn in www.net4india.com (a company from where we have registered domaim name and taken space)
    My problem is i am not able to send mail through my mail server (loyalindia.co.in)but i am receiving mails from any server.
    My network design is as fallows:-
    ADSL (WAN)59.181.103.220, ADSL (LAN)59.181.103.221. Pix 506e (out) 59.181.103.222, Pix 506e (in) 192.168.1.1. My domain mail server loyalindia.co.in (Exchange server) ip 192.168.1.2
    I am tryied with (ADSL)natting and without natting but the problem is same.
    If i am removing the pix 506e and directly connecting the server to adsl i am able to receive and send mails properly.
    can anybody who can support me?.

    Hello
    I think there won't be one QUCK START to get all of this up and running, there are multiple examples on the following page, a few that might help would be:
    http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/prod_configuration_examples_list.html
    PIX/ASA : Connecting Three Internal Networks with Internet Configuration Example
    PIX/ASA : Connecting Two Internal Networks with Internet Configuration Example
    ASA 7.x/PIX 6.x and Above: Open/Block the Ports Configuration Example
    PIX/ASA 7.x: Enable VoIP (SIP, MGCP, H323, SCCP) Services Configuration Example
    PIX/ASA 7.x and FWSM: NAT and PAT Statements
    PIX/ASA 7.x and later : Port Redirection(Forwarding) with nat, global, static and access-list Commands
    Configuring PIX Firewall with Mail Server Access on the DMZ
    Configuring the PIX Firewall with Mail Server Access on Inside Network
    Please rate if you find the post helpful.
    Regards
    Farrukh

  • Manual for PIX 506E?

    Hi everyone! I just became in charge of a PIX 506E, which I have no experience with. I was not told how it was set up, what the password is, etc...Oh, and the dongle for the console connection is non-existent as well.
    On Cisco's website, I can't find any manuals for it. The only documentation I could find was a quick setup guide, which is not helpful at all if it is already set up.
    Basically, I am looking for any help anyone can provide so that I can get into the interface for the PIX 506E so I can see how things are set up and to change things in the future. Thank you in advance!

    This could be a long journey or a short one, but for sake to help you here we go..
    When I say long journey it is because all depends on what type of resources you have at hand, at least you have us in netpro, but more specifically if you do not know the admin password for the PIX that is number one headache, you need password recovery procedure, please try to make an effort to obtain the password to not go through all these procedures, if you cannot then you need password recovery .
    See password recovery.
    http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_password_recovery09186a008009478b.shtml
    Please have handy these tools
    1- Console cable to connect to COM port in PC and PIX console port
    2- Terminal emulator - hyperterminal
    3- Mini hub to connect your PC and pix pysical interface to it
    4- tftp server software running on your PC
    Follow instructions on link.
    As for instructions about the PIX there are hundreds of documentation in Cisco website, we can direct you to them but first you need to gain access to PIX.
    HTH
    -Jorge

  • PIX 506e - cannot browse startup.html

    I just got a PIX 506e from a friend that was not longer using it. I'm trying to get started with the configuration page. I've reset it to factory defaults, rebooted and connected up ethernet. I can ping the device at 192.168.1.1 and access it via console. I browse the site https://192.168.1.1/startup.html, get the invalid ssl certification, get a login prompt (user/pass) and as the document says I leave it blank. As soon as I hit ok it goes to the 404 error Page Not found.
    Thanks in advance!
    second part, anyone have a good article/document on standard configurations via cli? I worked my way through
    http://www.dslreports.com/faq/15785 but didn't have any luck. Thats why I want to start with the web config then work into CLI.

    I meant to reply sorry.
    I found out that its 6.3 but that the previous owner removed PDM. I found the download on cisco HOWEVER I don't have an account so I have no way of actually downloading the PDM or 6.3 with pdm bin file.
    do you know where I can get that?
    thanks

  • Vpn connected to Pix but no Internet Access after connection

    Hi,
    We have just changed over our firewall to a Pix 515. The VPN Client (4.6) has been set up and remote users can connect ok and authenticate using Windows IAS. However, once they connect to the VPN they can no longer surf the internet. Our support company are saying that this is impossible because it can cause spoofing. Is this really impossible on the Pix? Is there a way that the remote user can surf the internet via their local connection when connected on the VPN?
    Many thanks for looking.
    PJ.

    Hello,
    It is possible to connect through Cisco VPN client while keep using the internet. You have to use something called Split Tunneling. Below you can find a link how to configure split tunneling:
    http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172787.html
    http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080702999.shtml
    Hope this helps,
    Appreciate your rating,
    Regards,

  • Client connecting through firewall

    Hi
              We have two clustered servers.Our client is connecting through
              firewall NAT. When iam connect to first server the response is very slow and
              at the same time clustering is not working.If i stop the second server the
              response fast .
              The same configaration is working fine when my client is local.
              Can you explain the reason for this problem ?
              Presently iam using weblogic 6.1 version.
              Thank you
              

    OK I spoke too soon. The user looked like it was working but it was working because it matched another IAS policy further down the list. It seems as though the PIX refuses to use ms-chap of any sort. If I include the authentication type in the VPN policy conditions as ms-chap, it skips the VPN policy I am using to authenticate this. If I remove it, then it gives an invalid authentication type as if whatever the PIX is sending the IAS server does not understand as ms-chap.
    It seems like the PIX authentication is totally wrong for use with IAS. What else do I need to add to this configuration to gewt it to work with ms-chap of any kind? I really don't get it.

  • Problem with socket connection through Java Embedding...

    We are trying to create a simple socket connection to a socket server through BPEL PM using the Java Embedding component.
    BPEL Process : Client makes an asynchronous request. Passes an input variable. The input variable is sent to the Server Program through a socket connection through the Java embedding component.
    Server: We are running a simple Socket Server program from command prompt.
    The code below works fine as long as we do not try to receive a response from the server (Commented Code).
    If we uncomment the code and try to receive a response, it refuses to create an instance for the BPEL Process. And sometimes restarts the BPEL Server.
    Client Code:
    String msg="NONE";
    try{
    org.w3c.dom.Element input = (org.w3c.dom.Element) getVariableData("inputVariable","payload","/client:clientProcessRequest/client:input");
    msg = input.getNodeValue();
    Socket clientsoc=new Socket("ServerIP",1000);
    PrintWriter out1=new PrintWriter(clientsoc.getOutputStream());
    out1.write(msg);
    out1.flush();
    BufferedReader cin1=new BufferedReader(new InputStreamReader(clientsoc.getInputStream()));
    msg=cin1.readLine();
    setVariableData("outputVariable","payload","/client:result",new String(msg));
    clientsoc.close();
    catch(UnknownHostException e)
    System.err.println("Don't know about host: dev.");
    System.exit(1);
    catch (IOException e)
    System.err.println("Couldn't get I/O for "+ "the connection to: dev.");
    System.exit(1);
    }

    Repost

  • HT1430 I CANT GET my IPad to connect to my WiFi and now I can't get it to go back so I can connect through iTunes- any ideas??

    cannot get iPad to connect to WiFi because I can't find the password-and now i can't get the iPad to reset to be able to connect through iTunes--help

    cannot get iPad to connect to WiFi because I can't find the password-and now i can't get the iPad to reset to be able to connect through iTunes--help

  • Help I purchase an Ipad yesterday I amusing internet connection through a netgear wired to my home computor since yesterday I am unable to open my emails or access my bank account ps I am not technical I am with orange broad band and have followed their i

    Help I purchased an ipad yesterday I am using internet connection through a wired up netgear router through my pc.Since then I cannot open my hotmail emails or access my online banking on wired pc and the navigator on ipad not working.
    I would appreciate help I followed all directions that Orange provided with netgear router

    Something here may help
    http://www.apple.com/uk/support/ipad/contact/
    pick a subject from left hand panel
    and this
    http://manuals.info.apple.com/en_US/ipad_user_guide.pdf

  • HT2250 I have been able to get my MacBook Pro to print wirelessly through my Airport device. How do I make it so other computers (non-Mac) can also print wirelessly as well? They are able to connect through my wireless network but can't print.

    I have been able to get my MacBook Pro to print wirelessly through my Airport device. How do I make it so other computers (non-Mac) can also print wirelessly as well? They are able to connect through my wireless network but can't print.

    Well, you could install the drivers to the wireless printer in you other computers.
    blue apple > System Preferences... > sharing
    check printer sharing.

  • How can i airplay from my mac connected through ethernet to an aple tv 2 on wifi

    Hi everyone..
    im having troubles using Airplay on my mac.. i connect my mac to the internet and home network using an ethernet connection to my router (non apple branded router) .. my apple tv 2  is connected to my home wifi network from the same router.. when i first set up my apple tv.. i was able to see the Airplay icon on itunes and it would let me Airplay media from my mac to my apple tv.. however.. it disconnects after a little while.. same thing with viewing my itunes library from apple tv.. i was able to detect my shared library from the apple tv.. i was able to play some media but then it disconnected after some time.. but now.. the Airplay icon doesnt show up in itunes anymore.. and i cant see my shared library from my apple tv neither.. ive looked around for a solution and followed the tip to turn the ipv6 off.. it worked for some time but now the problem is back..
    i know the obvious solution is to connect my mac to the same wireless network as my apple tv.. but i would like to keep it connected through ethernet..
    Mac OS X Lion 10.7.4
    Apple TV 2 software version 4.4.4
    Thanks in advance

    thisguy. wrote:
    ......i know the obvious solution is to connect my mac to the same wireless network as my apple tv.. but i would like to keep it connected through ethernet.........
    I wouldn't say that was the obvious answer at all, my Mac is connected by ethernet and 6 of my 7 Apple TV's are connected by wifi, I haven't had any of your problems. The problem is most likely on your network.
    Intermittent problems
    Intermittent problems are often a result of interference. Interference can be caused by other networks in the neighbourhood or from household electrical items.
    You can download and install iStumbler (NetStumbler for windows users) to help you see which channels are used by neighbouring networks so that you can avoid them, but iStumbler will not see household items.
    Refer to your router manual for instructions on changing your wifi channel or adjusting your multicast rate.
    There are other types of problems that can affect networks, but this is by far the most common, hence worth mentioning first. Networks that have inherent issues can be seen to work differently with different versions of the same software. You might also try moving the Apple TV away from other electrical equipment.
    Consistent Problems
    A frequent cause of consistent failure to enable AirPlay or HomeSharing at all, is the service being blocked on the network. Make sure your network isn't hidden, has a unique name, that MAC address authentication is disabled, security is set to use WPA 2 Personal and that there is only one router/device acting as a DHCP server and providing NAT services.
    Make sure your router/computer allows access over the following ports
    Port
    Type
    Protocol
    Used By
    80
    TCP
    HTTP
    AirPlay
    443
    TCP
    HTTPS
    AirPlay
    554
    TCP/UDP
    RTSP
    AirPlay
    3689
    TCP
    DAAP
    iTunes/AirPlay
    5297
    TCP
    Bonjour
    5289
    TCP/UDP
    Bonjour
    5353
    TCP/UDP
    MDNS
    Bonjour/AirPlay
    49159
    UDP
    MDNS (Win)
    Bonjour/AirPlay
    49163
    UDP
    MDNS (Win)
    Bonjour/AirPlay
    Refer to your router manual/manufacturer for any settings that are specific to that model.
    Another frequent cause of consistent failure to enable AirPlay or HomeSharing at all, is security software, in many cases configuring it correctly, disabling it or even uninstalling it can help, but in some cases the security software can cause problems that simply reconfiguring, disabling or uninstalling cannot reverse.
    If you are consistently unable to activate AirPlay, have tried all the steps in this article and have security software installed on your system, you might benefit from contacting its provider or participating in any online forums they run to discuss the matter with them.

  • My IPOD and Macbook Pro both will not connect to the Itunes store through Itunes says no internet connection, but I can connect through safari and I have a internet connection

    My IPOD and Macbook Pro both will not connect to the Itunes store through Itunes says no internet connection, but I can connect through safari and I have a internet connection

    As I mentioned above, I am not very tech savvy so I have no idea why a wireless protocol would be showing up there, I'm just listing everything I see in hopes that someone might know something I can try. This is why I am asking for help here - I'm not sure what has happened that has made me unable to connect, especially since it seemingly occured while nobody was using the computer.
    I guess I should clarify that I'm not a total hillbilly- normally my firewall is set to 'on', but I set it to 'off' to try and troubleshoot the issues here as I was told that sometimes it can interfere with the computer's ability to connect to the internet. If this is not the case and firewall does not affect anything, I will turn it back on while I try to fix this.
    I have tried the method you mentioned above a few times - I actually contacted my ISP earlier this week and they recommended resetting the router like that. They didn't mention any known network issues.

  • I can print from my macbook pro using airport express usb connected printer, however my iPad is looking for an airprint printer.  Can I direct the iPad to the usb connected printer.  Both macbook and iPad confirm a wifi connection through the airport exp.

    I can print from my macbook pro using airport express usb connected printer, however my iPad and iphone are looking for an airprint printer.  Can I direct the iPad/iphone to the usb connected printer.  Macbook iphone and iPad confirm a wifi connection through the airport express.

    You will need to install an App like Print Central on the iPad to try to print to the printer. It will allow you to print to most printers. Check with their support folks if you need more info.
    PrintCentral for iPad on the iTunes App Store

Maybe you are looking for

  • Edit in Photoshop CS6 - after saving, file ends up in a seperate directory in Library module but ...

         Hi, I'm getting this really annoying thing when I edit and save a file in Photoshop CS6 from Lightroom. After I save and return to LR4.2 in Windows Explorer it puts the TIFF in the same directory next to the original RAW file as it should, howev

  • Adobe Drive 5 Install Failed on Mac

    When installing Adobe Drive 5 on a Mac and get Installation Failed with the fallowing error Summary: Exit Code: 7 Please see specific errors below for troubleshooting. For example,  ERROR: -------------------------------------- Summary --------------

  • How to implement this scenerio in the workflow - More details given Inside?

    We are implementing a simple PO release workflow in ECC 5.0. The workflow just has a decision step and a release step. We have implemented the workflow in our system and it seems to be working fine. Problem Statement:     The client has many Purchase

  • Tricky Scenerio in AS 3.0

    Hi Guys I am trying to accomplish something which I think is little tricky for me in AS 3.0. Please help me out if you guys have any idea how to solve it. I am putting multiple instances of UILoader (containing videos) on the main stage and we can pu

  • Using RoboHelp with Flex

    Does anybody know how to use RoboHelp with Flex? I'm a Flex developer and am new to RoboHelp, and am trying it out to create some online help for my Flex application. I've searched, and also tried a couple of tutorials, but so far I haven't found any