RE: [fw-wiz] PIX DMZ inter-access via outside IP address

From: Keith Anderson (keith_at_purescience.com)
Date: 12/07/03

  • Next message: Andy Lyakhovetskiy: "RE: [fw-wiz] PIX DMZ inter-access via outside IP address"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Sat, 6 Dec 2003 22:41:09 -0700
    
    

    AS a follow-up, the problem ended up being a routing issue. Packets
    destined to the outside interface would get ignored by the router because
    they were assumed to be destined for a device on that domain. The solution
    was to use non-Internet routable addresses between the PIX and the router.
    Now that it has a different IP class, the router redirects those packets
    back to the PIX, and communication using the Internet addresses works on all
    interfaces.

    Seems obvious now that it was pointed out to me. More evidence that I need
    a vacation.

    I'll post the configs if anyone wants to see the finished product.

    > THE KILLER PROBLEM: The two servers in the DMZ CAN NOT access
    > each other
    > using their public Internet addresses. They can use their
    > 192.168 addresses
    > just fine, but not their public addresses.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Andy Lyakhovetskiy: "RE: [fw-wiz] PIX DMZ inter-access via outside IP address"

    Relevant Pages

    • RE: Cisco IOS vulnerability
      ... You are vulnerable unless you have deny statement which blocks all ... packets other than say ICMP or IPSEC coming to the router interface ... Even though the packets targeted *at* the routers interface is only ...
      (Incidents)
    • Re: Smoothwall may not be forwarding port 80
      ... On the red interface is an adsl router. ... PORT STATE SERVICE ... dropping the packets, or that the forwarding does not work correctly. ...
      (comp.security.firewalls)
    • Re: Nmap questions concering my router
      ... It's a bit off topic - but down at the Ethernet level, the packets are ... so your router masquerades for you. ... it may differ from other applications - we just send data to a network ... >> the Ethernet header is the MAC address of the 10.0.0.138 interface. ...
      (comp.security.firewalls)
    • Re: adsl+sdsl+cable?
      ... Short answer: good luck:) ... Because the outgoing packets will always have the IP ... address associated with the originating interface, ... The server would see the router as the source ...
      (alt.os.linux.suse)
    • Re: Interface errors
      ... input packets with dribble condition detected ... 685 output errors, 846589 collisions, 2 interface resets ... Some idea of how busy the interface is supposed ... This indicates that the router has been ...
      (comp.dcom.sys.cisco)