PIX 501 Outbound Site Acess Problem
Hi all
I'm fairly new to the PIX so be patient with me! I've just installed a PIX 501 at a SMB client running a windows SBS 2003.
Out of the box the PIX pretty much worked for the outbound traffic and inbound was sorted after few weeks of research and a bit of trial and error ;-)
However I have a few remaining problems (which are probably related) and I need to get them solved.
All problems are with OUTBOUND trafic (or the return of), ie the client behind the firewall is having problems accessing specific external website and services,
Examples are below and then the network topology after if you need it.
The only outbound rule is the default factory implicit one ie src:any dest:any interface:inside(Outbound) Service:ip
There are a number of inbound rules to allow access to the OWA & OMA server (80/443) and also VNC (5800/5900) The final incoming rule being a deny any any ip one. This seems to be working ok.
I've also installed a syslog server and captured the logs from one of our failed sessions but am having trouble seeing a cause.
Example 1: Natwest Web Banking The client is able to surf to
Example 2: RemotelyAnywhere on Remote machine They have a remote salesman who has Remotelyanywhere on his machine, The client accesses it via https://externalip:3000They are able to see the dashboard, able to use file transfer but when remote accesss part starts you see the remote desktop but have no control.
I set the PIX logs on Debugging and captured the output from Example 1 : (it's also mixed with some server traffic ie dns lookups). I see lots of "Built Outbound", "Built Dynamic","Accessed URL" and "Teardown" lines but am having trouble deciphering any root cause.
Any help or pointers would be appreciated
Network Topology
BT Voyager 205 ADSL Modem - Cisco PIX 501 - Internal Lan Inc SBS2003
BT Voyager 205 Modem External IP : Dynamic Internal IP : 192.168.0.1 DHCP : ON
Cisco PIX 501 (6.3) Outside IP : 192.168.0.2 Inside IP : 192.168.1.1 DHCP : Off Using PAT
Small Business Server 2003 IP : 192.168.1.2 DNS : ON DHCP : ON WINS : ON Gateway : 192.168.1.1
Clients IP : 192.168.1.10 - onward (DHCP Assigned) DNS / WINS : SBS Server (192.168.1.2) Gateway : PIX (192.168.1.1)
If you need to see the logs or my config file drop me a reply
If you want to e-mail me remove NOSPAM from the address
Many thanks
Mark