GroupStudy.com GroupStudy.com - A virtual community of network engineers
 Home  BookStore  StudyNotes  Links  Archives  StudyRooms  HelpWanted  Discounts  Login
RE: Pix Firewall 515 access-list [7:86346] posted 03/25/2004
[Chronological Index] [Thread Index] [Top] [Date Prev][Date Next] [Thread Prev][Thread Next]


You should see in the logs if the traffic is coming from other ports - it
should be denied - syslog message 106023

-----Original Message-----
From: Peri Sophos [mailto:theperiman@xxxxxxxxxxx] 
Sent: 25 March 2004 11:52 AM
To: Andrew.Larkins@xxxxxxxxxxxxx; cisco@xxxxxxxxxxxxxx
Subject: RE: Pix Firewall 515 access-list [7:86346]

That's exactly what I did , but have seen no matches , Thanks though , I
will speek to the developers and make sure they are doing something to the
servers , so I can see if it is working or not , but thanks for the reply.

Cheers


>From: Andrew Larkins 
>To: Peri Sophos , cisco@xxxxxxxxxxxxxx
>Subject: RE: Pix Firewall  515 access-list [7:86346]
>Date: Thu, 25 Mar 2004 11:49:40 +0200
>
>access-list acl_dmz permit udp 1.1.1.0 255.255.255.0 2.2.2.0 
>255.255.255.0 eq 88
>  access-group acl_dmz in interface dmz
>
>
>As an example.......
>
>-----Original Message-----
>From: Peri Sophos [mailto:theperiman@xxxxxxxxxxx]
>Sent: 25 March 2004 11:40 AM
>To: cisco@xxxxxxxxxxxxxx
>Subject: Pix Firewall 515 access-list [7:86346]
>
>Hi Everyone,
>
>I wonder if you could help me with an access-list , I don't have much 
>experience on Cisco PIX firewalls , I have been asked to create an 
>access-list  to allow all my servers in the DMZ on address range ( 
>1.1.1.0
>) to talk to my active directory servers on address range (2.2.2.0) , 
>but must communicate with them on UDP port 88 which is the kerberos
protocol.
>
>I have tried a few commands but don't seem to work , perhaps someone 
>can guide me in the correct direction, this would be much appreciated.
>
>Regards Peri.
>
>_________________________________________________________________
>Find search terms fast with Keyword Highlight and Highlight Viewer!
>http://toolbar.msn.co.za?DI=1054&XAPID=2185
>**Please support GroupStudy by purchasing from the GroupStudy Store:
>http://shop.groupstudy.com
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html

_________________________________________________________________
Find Super 12 and other sports results on MSN Search! 
http://search.msn.co.za




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=86349&t=86346
--------------------------------------------------
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html