<rss version="2.0"><channel><title>Firewall Wizards (firewall-wizards) Mailing List</title>
<link>http://seclists.org/#firewall-wizards</link>
<description>Tips and tricks for firewall administrators</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Cisco ASA 8.0(3) with RSA SecurID</title><description>Posted by Todd Simons on Sep 15&lt;p&gt;


&lt;p&gt;
Hello All
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;
&lt;br /&gt;
&lt;p&gt;We&#39;re starting to evaluate the ASA 5500 series to replace our existing
&lt;br /&gt;
firewalls.  On our current firewalls we use RSA tokens for
&lt;br /&gt;
Authentication and WindowsAD for group Authorization.  Is this possible
&lt;br /&gt;
with the ASA?
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;
&lt;br /&gt;
&lt;p&gt;~Todd
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;&lt;p&gt;&lt;p&gt;</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0016.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0016.html</guid>
<pubDate>Mon, 15 Sep 2008 13:59:47 -0400</pubDate></item>
<item><title>Re:  VPNDMZ problem</title><description>Posted by  aditya mukadam  on Sep 5&lt;p&gt;


&lt;p&gt;
Ian,
&lt;br /&gt;
&lt;p&gt;If you can get to the LAN resources and not to the DMZ resources, you
&lt;br /&gt;
would need to check on :
&lt;br /&gt;
&lt;p&gt;1) Split tunneling : DMZ subnets should be allowed.
&lt;br /&gt;
2) NAT 0 statement should be configured for traffic between DMZ and pool IP
&lt;br /&gt;
3) Make sure there is a return route on the destination ( jus to...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0015.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0015.html</guid>
<pubDate>Fri, 5 Sep 2008 15:52:29 +0530</pubDate></item>
<item><title>Re:  PIX515 Inside NAT to private addresses through P2PTunnel</title><description>Posted by  aditya mukadam  on Sep 5&lt;p&gt;


&lt;p&gt;
Dave,
&lt;br /&gt;
&lt;p&gt;As correctly suggested by the group you would need to use *policy
&lt;br /&gt;
based static NAT*. Keep in mind, NATing happens first and then will
&lt;br /&gt;
hit the crypto map.So, define your crypto ACLs accordingly. Make sure
&lt;br /&gt;
there is no conflicting NAT-0 statement for the crypto traffic as,
&lt;br /&gt;
NAT-0 will take...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0014.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0014.html</guid>
<pubDate>Fri, 5 Sep 2008 15:57:10 +0530</pubDate></item>
<item><title>Re:  VPNDMZ problem</title><description>Posted by Ian Rarity on Sep 05&lt;p&gt;


&lt;p&gt;
&amp;lt;facepalm&amp;gt;
&lt;br /&gt;
&lt;p&gt;Yep, that was it.  The VPN split-tunnel uses a different ACL, which I&#39;d
&lt;br /&gt;
forgotten to update.  Everything&#39;s working now; thanks for responding.
&lt;br /&gt;
&lt;p&gt;Ta,
&lt;br /&gt;
IR.
&lt;br /&gt;
&lt;p&gt;*********************************
&lt;br /&gt;
Ian Rarity
&lt;br /&gt;
Technical Engineer
&lt;br /&gt;
ESPC (UK) Ltd.
&lt;br /&gt;
T: (44)131 624 8000
&lt;br /&gt;
F: (44)131 624 8509
&lt;br /&gt;...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0013.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0013.html</guid>
<pubDate>Fri, 05 Sep 2008 12:07:09 +0100</pubDate></item>
<item><title>Re:  Question on PIX replication</title><description>Posted by Farrukh Haroon on Sep 6&lt;p&gt;


&lt;p&gt;
This happened to me while working for one customer. It appeared to be a
&lt;br /&gt;
combination of failover link problems and perhaps even a software bug. I had
&lt;br /&gt;
to clear both boxes (write erase) and reload the configurations.
&lt;br /&gt;
&lt;p&gt;You can run the &#39;debug fover ...&#39; commands to get more meaningful results as
&lt;br /&gt;
to...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0012.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0012.html</guid>
<pubDate>Sat, 6 Sep 2008 13:07:28 +0300</pubDate></item>
<item><title>Re:  Question on PIX replication</title><description>Posted by Christopher J. Wargaski on Sep 4&lt;p&gt;


&lt;p&gt;
Hey Steve--
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;I haven&#39;t seen this one before, but be prepared to make those
&lt;br /&gt;
configuration changes again.
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;I would try the following:
&lt;br /&gt;
1a) power cycle the PIX that is in standby mode
&lt;br /&gt;
1b) do a write standby
&lt;br /&gt;
&lt;p&gt;2a) failing 1, try a manual fail-back to the primary...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0011.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0011.html</guid>
<pubDate>Thu, 4 Sep 2008 00:21:06 -0500</pubDate></item>
<item><title>Re:  PIX 6.1 xlate issues</title><description>Posted by Christopher J. Wargaski on Sep 4&lt;p&gt;


&lt;p&gt;
Hello Shiv--
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;I recently saw a PIX 515E become so overwhelmed with the number of NAT
&lt;br /&gt;
translations that it exhausted the memory it had and pretty much stopped
&lt;br /&gt;
passing traffic until the dynamic NAT table was cleared. It turns out that a
&lt;br /&gt;
virus on the inside had infected a...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0010.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0010.html</guid>
<pubDate>Thu, 4 Sep 2008 00:14:42 -0500</pubDate></item>
<item><title>Re:  VPNDMZ problem</title><description>Posted by Christopher J. Wargaski on Sep 4&lt;p&gt;


&lt;p&gt;
Hey Ian--
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Are you using split-tunneling with the VPN? If so, make sure that the ACL
&lt;br /&gt;
permits the DMZ.
&lt;br /&gt;
&lt;p&gt;On Tue, Sep 2, 2008 at 5:06 AM, Ian Rarity &amp;lt;Ian.Rarity_at_espc&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&lt;p&gt;&amp;gt; Hi,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; We&#39;re having a problem with our VPN; we have a PIX 515E with 4
&lt;br /&gt;
&amp;gt;...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0009.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0009.html</guid>
<pubDate>Thu, 4 Sep 2008 00:07:50 -0500</pubDate></item>
<item><title>Re:  PIX515 Inside NAT to private addresses through P2PTunnel</title><description>Posted by Robby Cauwerts on Sep 4&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;You can nat both source and destination at your site.
&lt;br /&gt;
&lt;p&gt;Have a look at the following example:
&lt;br /&gt;
http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800949f1.shtml
&lt;br /&gt;
&lt;p&gt;Keep in mind that when using this setup you will need to publish the natted
&lt;br /&gt;
address on your...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0008.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0008.html</guid>
<pubDate>Thu, 4 Sep 2008 22:13:14 +0200</pubDate></item>
<item><title>Re:  PIX 6.1 xlate issues</title><description>Posted by kevin horvath on Sep 3&lt;p&gt;


&lt;p&gt;
this sounds odd.  if it was an xlate issue with it getting overwhelmed
&lt;br /&gt;
then not just the dns server but other devices would also have
&lt;br /&gt;
connectivity issues.   You should increase you logging level to
&lt;br /&gt;
informational and see what the logs say when you encounter this issue.
&lt;br /&gt;
&amp;nbsp;I did have a...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0007.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0007.html</guid>
<pubDate>Wed, 3 Sep 2008 19:18:41 -0400</pubDate></item>
<item><title>Re:  PIX515 Inside NAT to private addresses through P2PTunnel</title><description>Posted by Chris Myers on Sep 4&lt;p&gt;


&lt;p&gt;
Will you be having bi-directional traffic? If so, then you will need  
&lt;br /&gt;
to do the reverse of this in the other direction. Outbound you need to  
&lt;br /&gt;
source NAT your 10.195.x.x (i.e local network) addresses to say  
&lt;br /&gt;
10.2.2.x, so the remote network does not see the src as its own  
&lt;br /&gt;
subnet, so they...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0006.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0006.html</guid>
<pubDate>Thu, 4 Sep 2008 17:13:52 -0500</pubDate></item>
<item><title>Re:  VPNDMZ problem</title><description>Posted by Chris Myers on Sep 4&lt;p&gt;


&lt;p&gt;
Hi Ian,
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;What is the revision you are running? If 6.3 then make sure that  
&lt;br /&gt;
there is a &#39;nat 0 access-list nonat&#39; .  This matches the ACL/ACLS  
&lt;br /&gt;
below depending on how many you need to build for nonat. You need a  
&lt;br /&gt;
nat 0 statement above for each...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0005.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0005.html</guid>
<pubDate>Thu, 4 Sep 2008 06:37:57 -0500</pubDate></item>
<item><title>Question on PIX replication</title><description>Posted by Steven Pfister on Aug 20&lt;p&gt;


&lt;p&gt;
I&#39;ve got a pair of PIX 525 in an active/standby configuration. I recently made some fairly large configuration changes to the active pix. Ever since then, I&#39;m getting some errors when writing the config to the standby unit. The error looks something like:
&lt;br /&gt;
&lt;p&gt;&amp;quot;At &amp;lt;date/time&amp;gt;, this active...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0004.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0004.html</guid>
<pubDate>Wed, 20 Aug 2008 16:23:13 -0400</pubDate></item>
<item><title>PIX515 Inside NAT to private addresses through P2PTunnel</title><description>Posted by Dave Arroyo on Aug 26&lt;p&gt;


&lt;p&gt;
I am not a PIX super user but know enough to get in trouble...
&lt;br /&gt;
I have a PIX515 that has a site to site tunnel to a client location where we will be accessing Citrix servers, they are using a 10.195.x.x network that overlaps with other private ranges allready in use throughout our network. I can...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0003.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0003.html</guid>
<pubDate>Tue, 26 Aug 2008 14:02:36 -0400 (EDT)</pubDate></item>
<item><title>PIX 6.1 xlate issues</title><description>Posted by B Shivanthan on Aug 20&lt;p&gt;


&lt;p&gt;
Hello there,
&lt;br /&gt;
I am using a PIX 6.1 (I know its quite old and replacement procedures already in place) and facing problems with xlates getting
&lt;br /&gt;
overwhelmed. I have this firewall serving our corporate network, where I have a proxy server, SMTP server, DNS server and about 1500 users
&lt;br /&gt;
browsing the...</description>
<link>http://seclists.org/firewall-wizards/2008/Sep/0002.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Sep/0002.html</guid>
<pubDate>Wed, 20 Aug 2008 09:02:25 +0300</pubDate></item>
</channel></rss>