Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX and FTP Access

Status
Not open for further replies.
Dec 20, 2004
18
US
Hello!

I "need" to configure our PIX firewall to allow FTP from an AS400 to a customer. Is this a good (read: secure) thing to do and if so, is this the correct way to do it:

static (inside,outside) 208.xxx.xx.x 10.1.xx.xx puts AS400 on the outside for registered ftp outbound only??

Do I need a conduit permit statement as well?? If so what would it look like?

Thank you!!
 
you will need an ACL to allow FTP to pass thru the PIX.

access-list 100 permit tcp any host 208.x.x.x eq 21

No need for a conduit statement. Just add the statement above.
 
* agreed...

Conduits= bad

Anytime you want to provide a service to the outside you require a static & ACL.

Where is the AS400 in regards to the PIX (inside/outside/dmz)?

Also look to see that fixup for FTP is enabled, or FTP will break :).

Best regards,
Ryan Lindfield
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top