Re: Pix and fixup problem.

From: secondie (secondie@gmail.com)
Date: Wed Aug 09 2006 - 12:20:34 ART


my oversight, question does say that standard port should be allowed
too. So no need for "no fixup protocol ftp 21" at all.

-secondie

secondie wrote:
> Why "no fixup protocol ftp 21" . Is this part of question to block
> service on port 21 or just being safe?
>
> -secondie
>
> Stefan Grey wrote:
>> How would you solve the following task??
>>
>> You have a FTP Server on the Outside that uses a non-standard port of
>> 2100 for the command channel. Configure the PIX to alow inside hosts
>> to connect to this FTP Server. They should also be allowed to connect
>> to FTP server running on the Standard port.
>>
>> the solution in trinetnt is:
>> fixup protocol ftp 2100
>> no fixup protocol ftp 21
>>
>> I am not sure if there is an error because as I read in univercd. no
>> fixup protocol ftp command doesn't permit the inside ftp sessions.
>>
>> _________________________________________________________________
>> Find a baby-sitter FAST with MSN Search! http://search.msn.ie/
>>
>> _______________________________________________________________________
>> Subscription information may be found at:
>> http://www.groupstudy.com/list/CCIELab.html



This archive was generated by hypermail 2.1.4 : Fri Sep 01 2006 - 15:41:56 ART