Jump to content

Трабл с PIX не форвардятся пакеты из outside в private

Добрый вечер!


Есть Cisco PIX Firewall Version 6.3(1)

Со стороны private сети есть хост, со стороны outside хосты, например, и

Обоим надо достучаться до 514 порта UDP на


Заведены соотвествующие кондуиты:


object-group network SYSLOG-SRV-USERS
  network-object host
  network-object host

conduit permit udp host eq syslog object-group SYSLOG-SRV-USERS



От хоста пакеты валятся исправно

(с помощью debug packet пакетики видно и на outside, и на private)


От хоста -- только на outside, на private полная тишина


#debug packet outside src dst proto udp dport 514

--------- PACKET ---------

-- IP --   ==>

        ver = 0x4       hlen = 0x5      tos = 0x0       tlen = 0x7a
        id = 0x63e      flags = 0x40    frag off=0x0
        ttl = 0x3e      proto=0x11      chksum = 0x2a85

        -- UDP --
                source port = 0x202     dest port = 0x202
                len = 0x66      checksum = 0xd03d


при замене на

debug packet private src dst proto udp dport 514

-- молчание


Буду благодарен за любые подсказки.

Edited by evghoul

Share this post

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.