Been thrown in to the deepend here - Pix Firewall

oldBastard

Expert Member
Joined
Jul 28, 2006
Messages
4,764
Reaction score
1,250
Location
Somewhere near your mom
Ok, help, again from PIX firewall guru's.

Pix firewall. The link is up and I can ping the server, from the PIX. This is a FTP server on the other side. I need to open the ports:

1. Control port 24025
2. Data ports 24026 - 24030

Ports to be bi-directional

Um, how on a PIX firewall?????
 
Last edited:
So you want to connect to a external FTP server? Why do the ports needs to be bi-directional? The pix is a stateful inspection firewall so only the outbound port needs to opened. The only reason you would open the inbound port is if someone needs to connect to a server in the DMZ from a external source.
 
Ok, help, again from PIX firewall guru's.

Pix firewall. The link is up and I can ping the server, from the PIX. This is a FTP server on the other side. I need to open the ports:

1. Control port 24025
2. Data ports 24026 - 24030

Ports to be bi-directional

Um, how on a PIX firewall?????

Ok first of, are you linking in to the firewall VIA Console or are you using somtething like ASDM?

If you are using ASDM it would be alot easier as you can see the log and you can configure VIA a GUI.

OK the ports you want to open, are they UDP or TCP.

Then you need to have a look. From which layer are you trying to communicate to the FTP server?. Inside, Outside or DMZ. Remember you will allow the source as the PC/subnet that needs to acces the FTP.

So go to your rules, add a new rule. Choose which layer. Source is which PC you want to acces it from or subnet. Destination is the IP of the of the FTP server/PC. port is tcp/24025 you can add the other ports aswell by typing tcp/port number.

I am sorry, I know I am not clear but I am not at work so I cant go into a firewall to do a step by step and I have not worked with a PIX since last year since I replaced all my PIX's with ASA's.

If I am not clear enough let me know and I will have a look Monday morning and try to explain step by step.
 
Ok first of, are you linking in to the firewall VIA Console or are you using somtething like ASDM?

If you are using ASDM it would be alot easier as you can see the log and you can configure VIA a GUI.

OK the ports you want to open, are they UDP or TCP.

Then you need to have a look. From which layer are you trying to communicate to the FTP server?. Inside, Outside or DMZ. Remember you will allow the source as the PC/subnet that needs to acces the FTP.

So go to your rules, add a new rule. Choose which layer. Source is which PC you want to acces it from or subnet. Destination is the IP of the of the FTP server/PC. port is tcp/24025 you can add the other ports aswell by typing tcp/port number.

I am sorry, I know I am not clear but I am not at work so I cant go into a firewall to do a step by step and I have not worked with a PIX since last year since I replaced all my PIX's with ASA's.

If I am not clear enough let me know and I will have a look Monday morning and try to explain step by step.

Shot thanx, you have given me an idea on a PIX. Got somebody to help me anyways and he also explained to me.

You could try Firewall Builder GUI to generate the correct PIX settings.
http://www.fwbuilder.org/

Thnax, will try it out.

Never used it so cannot vouch for it.
 
Top
Sign up to the MyBroadband newsletter
X