R: [fw-wiz] PIX DMZ inter-access via outside IP address

From: edp (edp.lists_at_acerbis.it)
Date: 12/11/03

  • Next message: Lee T. Christie: "[fw-wiz] PIX Authentication Question"
    To: "'Keith Anderson'" <keith@purescience.com>
    Date: Thu, 11 Dec 2003 17:47:52 +0100
    
    

    > The solution was to use non-Internet
    > routable addresses between the PIX and the router.

    Solution suggested to me in the past, but very problematic if you use
    the pix also as vpn/ipsec public termination device, thus requiring a
    public ip address.

    In a scenario similar to that depicted by you, my quick and dirty
    workaround was to configure two ip addresses for each dmz machine (the
    internal private one and another ip corresponding to the public one) so
    the servers was able to communicate without routing tricks with both
    addresses.

    However, when possible and when communication without using name
    resolution isn't mandatory, I tend to use a dns split horizon solution.

    .FT

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Lee T. Christie: "[fw-wiz] PIX Authentication Question"

    Relevant Pages

    • RE: Router with security features
      ... Subject: Router with security features ... Cisco makes an even cheaper and smaller pix firewall. ... Pix 520's it just does not come with more powerful hardware. ...
      (Security-Basics)
    • RE: Router with security features
      ... Subject: Router with security features ... Well when looking at firewalls you have to understand that a PIX is a PC ... If you want the firewall to work well, ...
      (Security-Basics)
    • RE: PIX Question
      ... to say on the locking down a router and yes the firewall will block internal ... With out some sort of filtering on the ... edge router you will still leave yourself open to certain attacks. ... Subject: PIX Question ...
      (Security-Basics)
    • Re: Question on dynamic routing and PIX VPN
      ... >servers are behind a PIX and I need to use an IPSEC VPN to link the sites. ... Those customers are insisting the fact they ... I have a router which I own. ... Each packet coming in through one of the decidated SDSL interfaces ...
      (comp.dcom.sys.cisco)
    • Re: PIX 506E as a router
      ... to use it as a simple router? ... as you *need* the responses coming from the WAN unless ... incoming packets that are responses to outgoing packets (a ... PIX 506E do -fairly- well in such configurations, ...
      (comp.dcom.sys.cisco)