Re: [fw-wiz] 2 PIXes with their interfaces sharing the same switch and on the same VLAN.
- From: Marjan Naumovski <marjan.naumovski@xxxxxxxxxxxxx>
- Date: Tue, 04 Aug 2009 08:19:42 +0200
Hi Rudy,
Are the two pix'es connected in other way besides the wan? For example A
"lan" and B "dmz" are in the same network. If they are connected via
these interfaces that explains why changing the gateway works. If you
enable nat on B "dmz" you should be able to connect to the server.
On Sat, 2009-08-01 at 08:19 +0700, Rudy Setiawan wrote:
Hi all,--
I have some problem that I need some solution/advice :)
I have two PIX'es
* PIX A WAN is connected to Provider A
* PIX B WAN is connected to Provider B
* PIX A inside interface has the IP address of 10.15.1.1
* PIX B DMZ interface has the IP address of 10.15.1.2
* PIX B inside interface has the IP address of 10.17.1.1
* Subnet mask for all of the IP addresses 255.255.0.0 or /16
I disabled nat by way of nat 0 access-list to both PIXes and the
interfaces as well (except the WAN).
I have a "ip permit any any" applied to all interfaces except the WAN,
A user with IP 10.17.1.2 has a gateway of 10.17.1.1 is able to ping a
server in 10.15.1.10 (the server has a gateway of 10.15.1.1) but is
unable to ssh to the server.
But if I changed the gateway of the server to 10.15.1.2, then the user
is able to ssh to the server.
What am I doing wrong here?
Thank you so much in advance for the help.
Regards,
Rudy
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Marjan Naumovski
System & Security Engineer
ISP Neotel - Skopje
marjan.naumovski@xxxxxxxxxxxxx
Tel: +389 2 5511 141
mob: +389 75 446 503
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- References:
- Prev by Date: Re: [fw-wiz] 2 PIXes with their interfaces sharing the same switch andon the same VLAN.
- Next by Date: Re: [fw-wiz] sla with source route
- Previous by thread: Re: [fw-wiz] 2 PIXes with their interfaces sharing the same switch and on the same VLAN.
- Next by thread: Re: [fw-wiz] sla with source route
- Index(es):
Relevant Pages
|