Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > PIX 515 Inbound/Outbound access list confusion

Reply
Thread Tools

PIX 515 Inbound/Outbound access list confusion

 
 
vincehgov@gmail.com
Guest
Posts: n/a
 
      03-08-2006
I'm trying to setup my company firewall to allow connections that is
described as:

OUTSIDE IPs are: A and B
These are NATed to the INSIDE and the DMZ

The firewall should operate as followed:
OUTSIDE to DMZ allow SMTP
OUTSIDE to INSIDE allow SMTP and HTTPS
DMZ to INSIDE allow LDAP and SMTP

All traffic going from INSIDE to DMZ, INSIDE to OUTSIDE, and DMZ to
OUTSIDE is permitted.

After reading the Cisco ASA and PIX Firewall Handbook, I created 6
access lists; an Inbound and an Outbound for each interface. As I
understand it, the Inbound access list for the DMZ interface controls
connections originating from the DMZ to the INSIDE as well as
connections originating from OUTSIDE to the DMZ, which is very
confusing. This didn't work, despite the logic being correct. Every
behavior was correct except that I couldn't access OUTSIDE from DMZ on
any port. The security levels listed from lowest to highest are
OUTSIDE->DMZ->INSIDE.

Then, I decided to only have 2 access lists. One would permit SMTP and
HTTPS from A to the INSIDE address and it would also permit SMTP from B
to the DMZ address. That one was applied to the OUTSIDE interface on
the Inbound traffic. The other access list would Allow LDAP and SMTP
from the DMZ to the INSIDE and at the same time take on the role of the
outbound access list and allow HTTP, HTTPS, SMTP, and DOMAIN from the
DMZ to the OUTSIDE. This access list was applied to the DMZ interface
on the Inbound traffic.

My question is: How is it possible for the Inbound access list on the
DMZ interface to affect the Outbound traffic? If I took the lines that
explicitly allow outbound traffic from the DMZ to the OUTSIDE off the
DMZ access list, outbound requests break.

Any help or insight would be very appreciated.

Vince

 
Reply With Quote
 
 
 
 
shahidsheikh....com
Guest
Posts: n/a
 
      03-08-2006
Sounds like you are using the PDM to configure it. What I have found
out that it is usually good idea to look at the running configuration
when trying to explain why certain things don't work the way I would
expect them.

My suggestion would be to post your running config and I'm sure someone
will reply back with an explaination.

HTH,

Shahid

 
Reply With Quote
 
 
 
 
vincehgov@gmail.com
Guest
Posts: n/a
 
      03-08-2006
Shahid, thanks for the reply. I'm not using the PDM. I'm accessing
the pix via CLI. I'll post my config when I get back to my office.
However, the thing I'm most curious about is this. Can an ACL applied
to the inbound traffic of an interface affect the outbound connections
of that interface? If I create an outboand ACL allowing my DMZ to
access the internet and apply that to the outbound traffic of the DMZ
interface, it does nothing. However, if I put the same lines into the
inbound ACL and apply the inbound ACL to the inbound traffic of the DMZ
interface, the DMZ is able to access the internet. Strange behaviour I
believe.

Vince

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
PIX 515 - can Use VPN300 Client and PIX-to-PIX VPN at the same time? Stephen M Cisco 1 11-14-2006 02:03 PM
PIX 515 to PIX 515 via Internet & IPSec, should I get a VAC? Scott Townsend Cisco 8 02-22-2006 09:59 PM
PIX 515 'PIX-1FE=' Problems Michael Kiessling Cisco 4 07-13-2004 06:42 AM
pix 515 to pix 501 Cisco 2 02-05-2004 01:55 AM
PIX NIX : A simple static and access-list (below) seems to have prevented ANY access through the PIX to the web. J Bard Cisco 2 01-10-2004 06:44 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57