Cannot connect to internal network device using https with PIX 506e

Unanswered Question
Nov 20th, 2007

I have set up a SSL concentrator on my internal network with a fixed ip address, this device is accessed using https. It works fine on our internal network. Then on my PIX 506e I have configured a static route from the external ip address to the internal address and then an access rule to allow https traffic to the external address. When I go to https://external ip, I am not able to connect to the network device. Any ideas what I am doing wrong? See below for relevant config:

access-list outside_access_in permit tcp any host xxx.xxx.xxx.236 eq https

static (intf2,outside) xxx.xxx.xxx.236 SSL netmask 255.255.255.255 0 0

Everything has been configured via the GUI and saved to flash.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
jmia@ohgroup.co.uk Tue, 11/20/2007 - 06:13

Try...

access-list outside_access_in permit tcp any host xxx.xxx.xxx.236 eq https

access-group outside_access_in in interface outside

static (intf2,outside) tcp xxx.xxx.xxx.236 https https netmask 255.255.255.255 0 0

save with: write mem

And also issue: clear xlate

Hope it helps, pls rate posts if it does.

theplace Wed, 11/21/2007 - 15:28

Thanks for your help. I have made the changes, but still no luck. I cannot connect to the device externally via telnet, ping or https.

Any other suggestions, I am using a PIX 506e with PIX version 6.3(4).

Cheers

Andy

Actions

This Discussion