en mi Cisco PIX, tengo el siguiente relacionados.
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol http 80
fixup protocol smtp 25
access-list inbound permit tcp any host 24.239.101.13 eq www
access-list inbound permit tcp any interface outside eq https
access-list inbound permit tcp any interface outside eq smtp
access-list inbound permit tcp any interface outside eq pop3
access-list inbound permit tcp any host 24.239.101.13 eq domain
access-list inbound permit udp any host 24.239.101.13 eq domain (where domain = port 53)
nat (inside) 0 access-list inside_out_nat0
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) tcp interface www 136.146.156.10 www netmask 255.255.255.255 0 0
static (inside,outside) tcp interface smtp 136.146.156.10 smtp netmask 255.255.255.255 0 0
static (inside,outside) tcp interface pop3 136.146.156.10 pop3 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface https 136.146.156.10 https netmask 255.255.255.255 0 0
static (inside,outside) udp interface domain 136.146.156.10 domain netmask 255.255.255.255 0 0
static (inside,outside) tcp interface domain 136.146.156.10 domain netmask 255.255.255.255 0 0
http server enable
http 136.146.156.0 255.255.255.0 inside
- fixup protocol dns maximum-length 512
- fixup protocol ftp 21
- fixup protocol http 80
- fixup protocol smtp 25
-
- access-list inbound permit tcp any host 24.239.101.13 eq www
- access-list inbound permit tcp any interface outside eq https
- access-list inbound permit tcp any interface outside eq smtp
- access-list inbound permit tcp any interface outside eq pop3
- access-list inbound permit tcp any host 24.239.101.13 eq domain
- access-list inbound permit udp any host 24.239.101.13 eq domain (where domain = port 53)
- nat (inside) 0 access-list inside_out_nat0
- nat (inside) 1 0.0.0.0 0.0.0.0 0 0
- static (inside,outside) tcp interface www 136.146.156.10 www netmask 255.255.255.255 0 0
- static (inside,outside) tcp interface smtp 136.146.156.10 smtp netmask 255.255.255.255 0 0
- static (inside,outside) tcp interface pop3 136.146.156.10 pop3 netmask 255.255.255.255 0 0
- static (inside,outside) tcp interface https 136.146.156.10 https netmask 255.255.255.255 0 0
- static (inside,outside) udp interface domain 136.146.156.10 domain netmask 255.255.255.255 0 0
- static (inside,outside) tcp interface domain 136.146.156.10 domain netmask 255.255.255.255 0 0
- http server enable
- http 136.146.156.0 255.255.255.0 inside
No está seguro de lo que el puerto 443 no? ¿Por qué abrir ese? Además, como señaló Im utilizando el método de encabezados de host, por lo que aún no está seguro de por qué youd cada sitio web que se indican en un puerto diferente que no sea 80
(Si su servidor es la solución de todos los sitios al puerto 80 del servidor de entonces no sé qué sitio a donde ir. No se puede ejecutar varios sitios en el mismo puerto.)