Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

newbie question

Cisco PIX 515 version 6.3(3)

We have a hearing impaired employee who requires a VRS. The port requirements for communication are:

IN: 1720 TCP, 15328-15333 TCP/UDP

OUT: 1024-65535 TCP/UDP, 21, 389

I can't get this thing to work. I'm scratching my head trying to figure out how to do this. They are able to get out (the people on the other end can see us) but communication cannot find its way back in (we cannot see them).

Here is what the firewall is throwing back:

%PIX-2-106001: Inbound TCP connection denied from (outside ip address)/1720 to (our outside global address)/63666 flags RST ACK on interface outside

%PIX-3-106011: Deny inbound (No xlate) udp src outside:(outside ip address)/15332 dst outside:(our outside global address)/15332

I have this so far:

outbound 1 deny 0.0.0.0 0.0.0.0 0 ip

outbound 1 except (inside VRS camera IP) 255.255.255.255 0 tcp

outbound 1 except (inside VRS camera IP) 255.255.255.255 0 udp

apply 1 outgoing_dest

I've tried various commands to get the communication coming in. I won't bother posting that since it obviously doesn't work. I would like for those ports to only be open to the VRS camera device. Can anyone help me out with this please? They are waiting on me.

2 REPLIES
New Member

Re: newbie question

Looks like you need to set up a static from your inside vrs camera ip to an outside global address.

static (inside,outside) GLOBAL_VRS_IP INSIDE_VRS_IP

Hope that helps.

New Member

Re: newbie question

Is that the only command I'd need to type?

static xxx.xxx.xxx.xxx 192.168.0.49

Thanks for the response.

101
Views
0
Helpful
2
Replies