
D-2
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Appendix D TCP/IP Reference Information
Ports
• In this guide, the use of “address” and “IP address” are synonymous.
• IP addresses are primarily one of these values:
–
local_ip—An untranslated IP address on the internal, protected network. In an outbound
connection originated from local_ip, the local_ip is translated to the global_ip. On the return
path, the global_ip is translated to the local_ip. The local_ip to global_ip translation can be
disabled with the nat 0 0 0 command. In syslog messages, this address is referenced as laddr.
–
global_ip—A translated global IP address in the pool or those addresses declared with the
global or static commands. In syslog messages, this address is referenced as gaddr.
–
foreign_ip—An untranslated IP address on an external network. foreign_ip is an address for
hosts on the external network. If the alias command is in use, an inbound message originating
for the foreign_ip source address is translated to dnat_ip by PIX
Firewall.
–
dnat_ip—(dual NAT) A translated (by the alias command) IP address on an external network.
In an outbound connection destined to dnat_ip, it will be untranslated to foreign_ip. In syslog
messages, this address is referenced as faddr.
–
virtual_ip—(used with the virtual command) A fictitious public or private IP address that is not
the address of a real web server on the interface you are accessing. We recommend that you use
an RFC 1918 address or one you make up.
Ports
Literal names can be used instead of a numerical port value in access-list commands.
PIX Firewall uses port 1521 for SQL*Net. This is the default port used by Oracle for SQL*Net. This
value, however, does not agree with IANA port assignments.
PIX Firewall listens for RADIUS on ports 1645 and 1646. If your RADIUS server uses ports 1812 and
1813, you will need to reconfigure it to listen on ports 1645 and 1646.
Note To assign a port for DNS access, use domain, not dns. The dns keyword translates into the port value
for dnsix.
Port numbers can be viewed online at the IANA website:
http://www.iana.org/assignments/port-numbers
Table D-1 lists the literal values.
Ta b l e D-1 Port Literal Values
Literal
TCP or
UDP?
Value Description
aol TCP 5190 America On-line
/jointfilesconvert/354787/bgp TCP 179 Border Gateway Protocol, RFC 1163
biff UDP 512 Used by mail system to notify users that new mail is
received
bootpc UDP 68 Bootstrap Protocol Client
bootps UDP 67 Bootstrap Protocol Server
chargen TCP 19 Character Generator
Comentários a estes Manuais