cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1220
Views
0
Helpful
2
Replies

PIX 7.1(2) Access-list not working

damrut5763
Level 1
Level 1

Hello,

can someone help me I'm running 7.1(2) on PIX 515E UR and my access-list is denying port 8888 eventhough I have it open up is there a bug in the software for that port. Here is the access-list

access-list dmz_access_in extended permit tcp host ADP-1 object-group TIMECLOCKS eq 8888

I have other ports open for this connection and they work!

2 Replies 2

Patrick Iseli
Level 7
Level 7

Can you post the whole ACL and the error log message. Just this line itself will not help to figure out the problem.

sincerely

Patrick

dflick
Level 1
Level 1

I am assuming the following:

host ADP-1 is in your DMZ.

you can do "ping dmz ADP-1" and get a reply

TIMECLOCKS are on the inside.

you can do "ping inside " and get a reply

If the above is true, do you have a static that allows TIMECLOCKS to be seen in the DMZ?

Can you do a netstat -a on the ADP-1 server to see if it is listening on port 8888.

You are probably getting a "deny no connection" or a "no translation"

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card