Helps to configure the pix firewall 507e for e-mail access

Dear experts,

I called our provider cisco and ask for technical help regarding our current problem as we know on our set-up.

She told me to convey my concern to the Cisco TAC. My friends told me to post it here under discussion Netpro.

I am writing today to ask a few questions about my pix 506 firewall configuration.

To give the implementation Details pls find below and attached seizures of the show tech command.

We have subscribed the service DSL and Singtel give us 2 addresses valid public IP that is 203.125.100.246 255.255.255.252.

I used 203.125.100.246 for my external interface of my firewall pix and singtel assign 203.125.100.245 to the DSL router. In this case, we will only use PAT for internet connection.

Currently he works very well our Mail Server is resided in the Singtel Office having the ip address of 165.21.111.22. Not work that we can receive and deliver electronic mail on the internet, and we can also surf the internet.

Now we intend to put our mail in our own network server, because sometimes we encounter slowness on receiving and sending emails. Pls check on the IP address below

Our LAN IP address is 192.168.1.X 255.255.255.0

default gateway, which is the IP address of the firewall pix inside interface is 192.168.1.1

The new mail server IP address is 192.168.1.4.

Here's what I've done so far.

I created a static mapping for my mail server is here

public static 203.125.100.246 (inside, outside) 192.168.1.4 mask subnet 255.255.255.255 0 0

and modify the access list to allow smtp on our networks.

192.168.2.0 ip access list ACL_OUT permit 255.255.255.0 any

ACL_OUT list access permit icmp any host 203.125.100.246

ACL_OUT list access permit tcp any host 203.125.100.246 eq smtp

ACL_OUT list access permit tcp any host 203.125.100.246 eq pop3

ACL_OUT list access permit udp any host 203.125.100.246 EQ field

Access-group ACL_OUT in interface outside

After doing it... I have loss all the internet connection, the email does not work... so I deleted immediately. because it causes network failure.

I have rather edit it and create a static map like this.

public static 203.125.100.246 (exterior, Interior) 192.168.1.4 mask subnet 255.255.255.255 0 0

and modify the access list to allow smtp on our networks.

192.168.2.0 ip access list ACL_OUT permit 255.255.255.0 any

ACL_OUT list access permit icmp any host 203.125.100.246

ACL_OUT list access permit tcp any host 203.125.100.246 eq smtp

ACL_OUT list access permit tcp any host 203.125.100.246 eq pop3

ACL_OUT list access permit udp any host 203.125.100.246 EQ field

Access-group ACL_OUT in interface outside

Saw what it did not cause a failure of network or interruption. I thought that it will already work with the config, I keep it and this is the current config now... But when I change the POP and SMTP settings so that it points on 192.168.1.4 which is the new mail server on our LAN. his does not work.

To this day, we are in a discussion with my boss or not possible to create a static mapping on our new mail server address 192.168.1.4 to 203.125.100.246 which is already assigned as external IP address and is used for PAT.

We are asking your help to know how to set up our internal mail server statically match our public IP address that is already used for PAT.

Please check attached the tech release see the.

Thank you very much!

I'd appreciate your quick response.

Your truth.

Dennis Pelea

Dennis,

Can you please send to me your configuration full pix (unscrew sensitive information) to [email protected] / * /

I am puzzled, why this configuration does not for you. I have several clients who use a public ip address for external intf more than several other services that use this single ip address.

Thank you / Jay

Tags: Cisco Security

Similar Questions

  • Cannot configure the static IP address for Cisco Touch 8 "

    Hi all

    I found that I can not configure the static IP address for Cisco Touch on TC7.0.1 / 7.0.2 with the procedure described below.

    1. upgrade a codec (e.g. SX20 TC6.3 or less) and a touch paired with the codec for TC7.0.2.

    2. after the upgrade, désapparier (with the help of désapparier Touch button) touch and it reboot.

    3. tap on "IP settings."

    4. Select "Manual IP allocation".

    5. Enter the IP address, subnet mask, default gateway, and then press "Save".

    Even though we have configured the static IP address with the above procedure, IP allocation remains 'Auto' (= DHCP) and the IP address, subnet mask, default gateway is also empty.

    In this situation, the only way to configure the IP address for the Touch is to use the DHCP server.

    I guess many users uses the static IP assignment like us, so please fix it as soon as POSSIBLE.

    Best regards

    Kotaro Hashimoto

    Hi Kotaro,

    It is a known problem in TC7.0.1 and TC7.0.2. The id of the bug is CSCum82147.

    To work around the problem, set IP address you want the button before moving on to TC7.0.x.

    The bug has been fixed and will be included in the next version of the TC software.

    Kind regards

    Jonas Tysso

  • To block P2P traffic on the PIX firewall

    What will be the mechanism, and how we can block the traffic of P2P applications like eDonkey, KaZaa and Imesh etc on the PIX firewall.

    Hello

    You can find the info here:

    http://www.Cisco.com/en/us/Tech/tk583/TK372/technologies_tech_note09186a00801e419a.shtml

    I hope this helps.

    Jay

  • I just bought the DC Pro Acrobat full of desktop software only.  Have downloaded fine, but when I go to install the download, it is for me an "access violation at address 00000000. read of address 00000000 ". Can someone please?  Thank you!

    I just bought the DC Pro Acrobat full of desktop software only.  Have downloaded fine, but when I go to install the download, it is for me an "access violation at address 00000000. read of address 00000000 ". Can someone please?  Thank you!

    Hi Rob,

    What is happening in Mode safe? If you can install it in Mode safe mode then delete all entries in startup via msconfig as this could conflict with the program.

    If this does not work, saving all the data of your administrator account, you can delete the account and recreate it.

    Kind regards

    Rave

  • Please help to configure the router for internet connection 871W!

    Hello world!

    I just started styding for CCNA, so I'm totally new to Cisco stuff. Recently bought a router 871W and spent two days in a row trying to configure internet connection with no luck! I use the port console for the configs and SDM/CCP. Would be greateful if someone could tell me how to do simple configs of internet connection. I googled everything but it's still confusing. I can't assing all-IP ports FA 0-3. I used instead of the VLAN. But all tutorials use FA0 and when I try to assign an IP address to FA0 it gives me some L2 cannot be assigned or something... :/ And I am also confused at what address IP use for WAN.

    I connected the cable between the Modem and the LAN of the PC port and copied some IP addresses which I think I have to use to configure the router for internet connection. And here they are:

    ISP IP: 76.114.54.255

    SUBNET: 255.255.248.0

    GATEWAY: 76.114.48.1

    DHCP: 69.252.97.4

    DNS: 75.75.75.75

    75.75.76.76

    If you can, please help! Thank you!

    Hi david,

    Looks like your 871w can not get a dynamic IP address: % unknown DHCP problem... No possible allocation

    you could ask your ISP to perform a reset/clear MAC add and try again?

    also, kindly post lastest "show run".

    Edit: just to see you've updated your screenshot. could you add command under 4

    Mac-add 0001.4af9.8b83

  • Configure the PIX 501 for IDS

    I have a PIX 501 with wired high-speed LAN headquarters inside and outside. Which would be a solid policy IDS to enable and what interfaces it must be applied to? There will be other measures necessary to enable IDS?

    IDS on the PIX itself is very limited, it checks only 59 signatures listed here (http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/cmdref/gl.htm#xtocid9 under the section of signatures supported IDS). The signatures themselves are pretty basic.

    If you do not want to activate this, then for the signatures of attacks I would fix for drop/alarm/reset action, which is the default anyway.

    You will also need to set the logging to a syslog server and monitoring for any 4000nn messages in syslog, cause it event IDS.

  • My mind is wiped out. I'll put up pages in Photoshop 9.0 to be then placed in InDesign 4.0 for professional printing. Can you help me configure the proper color settings, and what PDF preset to use. And output parameters, etc. Thanx.

    My mind is wiped out. I'll implement the color pages in Photoshop 9.0 to be then placed in InDesign 4.0 for commercial printing in book form. Can you help me with the settings of color in Photoshop, that is to incorporate the color profile; convert in space work, Adobe RGB, etc. and which PDF preset to use, i.e. printing, PDF / X - 1 or 3, etc. Also, what I have to select the output settings such as the conversion of colors with the Destination or the printer deals with that. I know I asked a lot, so thanks in advance for any input or advice.

    Best regards, ScottyB34

    What are the settings of your printer wants? Some may deal with sRGB some want Adobe RGB Ctrl/Cmd-Shift-k in Photoshop, then choose North Amercian prepress 2

    He'll take care of the tags for you, or if sRGB is important, Norh American General Purpose 2.

    Here is a summary of the settings PDF and their meaning:

    When you are ready to create a PDF file from an application such as Illustrator or InDesign Adobe, we give you a list of the predefined PDF settings from which to choose. Well how do you decide which is the right choice? Well, let me explain what they do.

    Let's start with the smallest file size and the name of the type of the story. It is compatible with Acrobat 6, which means that anyone who has Reader or Acrobat 6 or above will be able to open the file. Now it converts everything in sRGB color which is a common space for color monitor.

    All RGB is truncated to sRGB, CMYK and spot colors also. So that means if you have a job to print, you can see some color shifts in this outgoing PDF. You must decide whether it is acceptable. He can't stand live transparency, not flattened. It downsize image content to 100 pixels per inch and this is part of how she made a reduced file size. It also uses aggressive JPEG compression of poor quality on the content of the image. So, you can see some of these rectangular JPEG artifacts.

    But it is how it gives you a reduced file size, and results are appropriate to be posted online or attached to an email.

    High quality printing has compatibility with Acrobat 5 and above. There is no color conversion. RGB RGB stays, rest spot, stays of CMYK CMYK spot and it supports live, not flattened transparency. It does not perform some downsampling to 300 pixels per inch. So, for example, if you placed an image which was 300 ppi and then set to scale up to 50 percent there actually a res then 600 pixels per inch.

    Well, this process would take half out these pixels. Therefore, it can create larger files but that makes it suitable for in the House of printing or sending Let's say a remote office if they want to print we tell cells leaves, or brochures, or something like. It's beautiful out on an internal printer.

    Print quality and high quality printing have similar names, so this may be a bit confusing, but print quality has compatibility with Acrobat 5 or higher. It converts the content of RGB to CMYK destination values according to what you specify as the destination.

    It is usually SWOP, S-W-O-p. It supports live, not flattened transparency. It performs the subsampling bicubic to 300 pixels per inch and because that it keeps at least 300 pixels per inch, which means that it can create some large files, but it is suitable for professional printing.

    Then we start to get into the presets named 'X '. 'X' is now for Exchange. They agree on specifications and the idea is to have a set of specifications if a PDF file is compliant to these specifications, we know it's going to be printable.

    We know that imaging devices are going to treat them properly. So this goes back to 2001, and which can seem a bit old, but bear with me. PDF/X-1 has a compatibility with Acrobat 4. I know, it sounds old. It converts RGB to CMYK content, it keeps the content of good tones. It flattens transparency. Downsize it at 300 pixels per inch. It can large enough crat files if you have large size images in your project and that it is suitable for professional printing.

    The idea behind X-1 is if you send a PDF file to an unknown printer, you do not know what are their capabilities, you send abroad, it will be able to be photographed on any device. No matter the age, it is, they can print. Over the years, the concepts of Exchange became more sophisticated the workflow and devices become more sophisticated.

    SP PDF / X-3: 2002, remains compatible with Acrobat 4 and that means that it flattens transparency, but it does not perform any color conversion.

    This means that it maintains RGB content, place remains in place, rest of CMYK CMYK. He still performed bicubic downsampling at 300 pixels per inch, and therefore, it can create large files. But this is suitable for commercial printing, if the printer signals you that it is present RGB content is correct.

    PDF / X-4: 2008 is compatible with Acrobat 7 and later. See, we're getting more modern. No color conversion. RGB RGB stays, stays CMYK CMYK, spot rest spot and it supports live, not flattened transparency.

    He still performs bicubic downsampling. Therefore, it can create large files because it maintains the pieces of the image to 300 pixels per inch or higher and it is suitable for commercial printing, as long as the printer tells you that RGB content is not serious and dynamic transparency is acceptable. Some older workflow does not support dynamic transparency, or they treat well, and that's why always ask. It is a special case in Illustrator, something called default Illustrator. Its compatibility is Acrobat 6 or higher.

    It does not perform the color conversion, everything continues like this. It supports transparency live, not flattened, and it also contains the original, editable Illustrator file in the PDF file. It preserves layers and it may be return, can be reopened safely in Illustrator and it's really the only PDF format you can do with safely. But it can create larger files, because you sort of two files for the price of one, they sometimes get huge.

    So what predefined PDF is Right For You? Well, if you want to send for printing, the first thing you should do is to ask your printer how they want the created PDF.

    They should be able to give you the plug for the creation of the PDF file. They may be able to give you job options files you can simply import and use as your preset target. But if it's a stranger the printer or the printer for some reason any said, well, I don't know, just make a PDF and this happens, well, choose the lowest common denominator to the PDF/X-1 test. Anyone can image that. If it is a more modern printer and up to date, especially if you send it to someone who uses digital presses, PDF/X-4 should be safe.

    I always go back to point one, ask the printer. If you send it as an attachment or you're going to post online, well, smaller size of file is a pretty clear choice. But remember this, you can start with one of these predefined parameters, and you can always edit it to customize your specific needs. So get to know the presets, understand the destiny of the PDF you create, and then make the best PDF that you can.

  • How to limit the ICMP on the PIX firewall.

    Guys good day!

    I have a dilemma with regard to limiting ICMP users browsing to other networks such as other demilitarized interns.

    I know that, to allow ICMP to pass through interfaces, you will need to create an ACL such as below:

    access-list DMZACL allow icmp a whole

    Users require this config ping a server on the DMZ, but it is a security risk.

    To minimize, I have a group of objects created in order to identify hosts and networks is allowed to have access to the echo-replies.

    Again, this is a problem since many host who extended pings just to monitor the connectivity server and its application.

    Do you have other ideas guys?

    As to limiting the echo answers on the PIX. As first 5 echo request succeed with 5 echo-replies and the rest would be removed.

    This could be done?

    Thank you

    Chris

    Hello.. I don't think you can do this by using an ACL on the PIX, however, you might be able to stop the ICMP sweeps by activating CODES signatures using the check ip command you... For more information see the link below

    Guidelines of use Cisco Intrusion Detection System (IDS Cisco) provides the following for IP-based systems:

    ? Audit of traffic. The application of signatures will be audited only as part of an active session.

    ? Apply to the verification of an interface.

    ? Supports different auditing policies. Traffic that matches a signature triggers a range of configurable

    actions.

    ? Disables signature verification.

    ? Always turns the shares of a class of signature and allows IDS (information, attack).

    The audit is performed by looking at IP packets to their arrival at an input interface, if a packet triggers

    a signature and the action configured does not have the package, and then the same package may trigger another

    signatures.

    Firewall PIX supports inbound and outbound audit.

    For a complete list signatures of Cisco IDS supported, their wording and whether they are attacking or

    informational messages, see Messages in Log System Cisco PIX Firewall.

    See the User Guide for the Cisco Secure Intrusion Detection System Version 2.2.1 for more information

    on each signature. You can view the? NSDB and Signatures? Chapter of this guide at the following

    website:

    http://www.Cisco.com/univercd/CC/TD/doc/product/iaabu/csids/csids1/csidsug/SIGs.htm

  • Help to configure the router Cisco 1941

    Help!

    I just bought a router cisco 1941, I understand, it came with the Cisco CP, but I don't know how get you to the part where I can use it.

    Also, how can I connect to the router directly without using the HyperTerminal console, all I want to be able to do is configure the address IP of the ISP and my IP address so I can use it for surfing the internet.

    Help, please.

    Hello

    Thanks for the screenshots and show the output! You will need a few lines of command for CCP to work:

    Configure the terminal

    username username privilege 15 secret PASSWORD

    IP http server

    local IP authentication

    Sent by Cisco Support technique iPad App

  • The upgrade of the PIX firewall

    I currently have two firewalls Pix 515 (v4.4 and v6.2). I want to update the v4.4, but am unable to download the software from Cisco. Whenever I try to download using the link 'download pix software', it times out.

    I have already set up a tftp server and plan on the use of monitor mode to perform the upgrade. I already did a "write net:" to save the current configuration. " In addition, the original configuration remains intact, or they will be lost after the upgrade.

    Thanks in advance.

    Looks like you may have a problem with the download or the browser proxy. Try another host and/or browser and see if it works better.

    Since the PIX 4.4 software and versions later, you can go directly to any newer version of the software. To preserve your config, but it's always a good idea to back it up before an upgrade as you did. The config in the PIX is actually not get converted when PIX is restarted with the new software - what happens the first time you do a "write mem" under the new software, it is so important to remember to do as part of the upgrade process. You can then check the config freshly recorded against your configuration of backup for all differences. In addition, it is important to check the Release Notes before upgrading, but if you have a config PIX relatively simple it will probably be fine. One thing you want to do is migrate away from lines on access lists. Cisco is a utility that allows to convert them for you, and it does a very good job as long as your config is not too complex, so I might suggest to give it a try and see how it works for you. The downloadable version of this utility must be on the same page as other PIX software download, and there are versions for Windows and Sun Solaris.

    Good luck!

  • Username in the Pix Firewall

    When I do a command 'See logging' in my Cisco Pix Firewall (6.3), I am able to see the message below

    605005: x.x.x.x/33652 for eth1:y.y.y.y/telnet for the user authorized login «»

    In the message above, why the user name is not printed?

    your config has.

    Console telnet AAA authentication GANYMEDE + | RAY | LOCAL '?

  • Where can I configure the level of logging for the file "Inbox Journal?

    The Siebel 8 shelf, he says:

    "To adjust the level of the log for troubleshooting Inbox file.

    * Siebel tools, set the logging level for the Inbox log file (Alias = InboxLog) 5 *. »

    But where exactly in Siebel Tools find that level of Log? Which object is the Siebel Bookshelf talk?

    Hello

    Loglevels are not configured in Siebel Tools. You need to configure with the siebel client. You can find a setting to "Server Configuration - Administration / Server / events»
    Search for "Inbox General Log Events". Set this parameter to 5. He thinks this should help you.

    At soon Andreas

  • Ping on the PIX firewall

    Is it possible to ping directly from low security high security without translations on a PIX?

    For example, 192.168.2.90 is currently natted to 10.0.0.4 by the pix. I want to ping directly from 192.168.2.4 to 10.0.0.4.

    I can certainly ping directly from 10.0.0.4 to 192.168.2.4.

    Please let me know if you would like to see the complete config.

    I hope I understand your question completely. You try to ping from one interface to another on your PIX. This URL explains how this can be done.

    http://www.Cisco.com/warp/public/110/31.html

  • VPN with usernames in the pix firewall

    Is there anyway to make my VPN connections in my specific user pix?

    I know it's possible with the concentrator 3000 but don't know if you can do it with a pix. I have about 10 people who need VPN in.

    Can each VPN cause a different password?

    Reason is: if I let go 1 person I don't want to have to worry about changing the passwords for all the world just deleting an account.

    Thank you

    Anthony

    In a PIX VPN connection should always be authenticated with a name of username/password extra for extra security. Up to v6.3 you used to have to store these names of user and password to an external Radius/GANYMEDE server, but to the point 6.3 now you can use the local user on the PIX database to store these.

    The commands are:

    > the client authentication card crypto LOCAL

    > user_name password

    You can have as many orders "... user name. "as you wish. If someone leaves your company simply remove it the name of the list.

  • Where can I configure the rule of naming for the columns of the child?

    I have the logic model below:

    https://www.dropbox.com/s/1eux01rrkmcn84f/child_logical.PNG

    When I have the engineer I get the following physical model:

    https://www.dropbox.com/s/pwl2zxkvuigdr5q/child_physical.PNG

    How can I configure that no entity name prefix must be added to the name column?

    Columns must be named create_ts, modify_ts, delete_ts and attribute_1. (upcase all is ok).

    I tried to change the model of standard naming for attribute relationships, but it has no effect.

    Can someone give me a hint?

    I found a way to resolve names with a custom transformation script.

    ceving: abuse of inheritance for the coating with SQL Developer

    But the behavior of the new Modeler data seems to be different from the old. I create a model with the old. And now I'm still working on the model by the new. And for some columns, not the name of the inserted table and other tables. This occurs in the same model. I think that there still is some sort of bug in the problem.

Maybe you are looking for