Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

http access via PIX

I am trying to config my PIX 501 OS 6.1(1) to allow only http traffic to go out with the following acl and applied to the inside interface.

access-list acl_in permit tcp x.x.x.x x.x.x.x eq www any

access-group acl_in in interface inside.

Once I apply this acl, I can't seem to get to any websites. Am I doing anything wrong here or missing any acl entries?????

Thanks for your help in advance.

6 REPLIES
New Member

Re: http access via PIX

have u allowed ur dns queries out of ur inside LAN, if u have a DNS server

outside.(not in inside LAN). if not u can add an entry as below and check if it works.

access-list acl_in permit udp any eq domain any

Regards,

Ashok Pawar H.S.

New Member

Re: http access via PIX

I am trying to access using the IP address....do I still need the DNS entry in the ACL??

New Member

Re: http access via PIX

Do you have NAT set up and a outside route?

New Member

Re: http access via PIX

Yes, I do have a NAT/Global setup as follows:

nat (inside) 1 192.168.1.0 255.255.255.0

global (outside) 1 interface.

I don't have any outside route other than the default ststic route that was created during the initial setup.

thanks........

New Member

Re: http access via PIX

You need to allow DNS to pass through unless you are using an internal DNS.

New Member

Re: http access via PIX

First, I strongly recommend that you sit down and think about what you're trying to accomplish. As was mentioned, DNS will almost certainly be required for most web applications and services. You may want other services as well.

Second, unless I'm missing something, I believe that your access list is incorrect. Try something like:

access-list acl_in permit tcp x.x.x.x x.x.x.x any eq www

The destination port is 80. I believe that you have specified it as the source port.

Hope this helps.

89
Views
0
Helpful
6
Replies