RE: [fw-wiz] fun problem - possibly not possible



-----Original Message-----
Subject: Re: [fw-wiz] fun problem - possibly not possible

If I follow the instruction/diagram correctly, the problem here is that
both the sprayer and
the destination host are on the same network, on the same firewall
interface, all configured
with private IPs and public NAT addresses.

What protocol(s) are you using Network Dispatcher for? I'm not sure I
understand why 1) Network Dispatcher has to reference the other servers by
their public addresses and not their DMZ addresses and 2) why you've got the
firewall doing NAT for the servers you're trying to load balance with
Network Dispatcher.


The sprayer can't ping the hosts it's listening for by their public IP
addresses, get an
error concerning NATs. Add an alias for those IPs on that DMZ interface,
get an arror about
routes...

If you were doing this with almost anything other than a PIX, this would
probably work the way you have it configured. But since a PIX won't route
or NAT across the same interface, it doesn't work. That said, I don't think
you need it configured that way in order for this to work.

PaulM




_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Inbound connections on a 515e without NAT
    ... I have a PIX 5i5E configured that permits outbound connections ... is we aren't doing NAT, and are using the same addresses inside as ... global 1 interface ... access-group permit_web in interface outside ...
    (comp.dcom.sys.cisco)
  • Re: NAT-T + VPN Tunnel
    ... >And the router on the outside has a static translation for the PIX ... >interface and a destination network somewhere on the Internet, ... Your NAT is probably ... assuming overloading and changing the port to one Cisco does not ...
    (comp.dcom.sys.cisco)
  • Pix Outside NAT
    ... I have a pix that connects to 2 internet links. ... I have been thinking of puting the 2nd link on a separate interface on ... direction) so that when my inside host replies it will reply to the NAT ...
    (comp.dcom.sys.cisco)
  • Re: PIX: NAT inside VPN tunnel (515e)
    ... > The PIX has one outside interface with a public IP address ... > administration reasons - i want to use NAT to hide my private ...
    (comp.dcom.sys.cisco)
  • double NAT??
    ... I configured the PIX to do nat as normal from the inside to the ... connected to the 1750 fast eth interface which is IP 192.168.70.1/24. ... So the PPPoE connection to the inet is definetly working. ...
    (comp.dcom.sys.cisco)