PIX 501 issue

PIX 501 issue

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
PIX 501 issue Chris.Fox 07-24-2006
|--> Re: PIX 501 issue Walter Roberson07-24-2006
Posted by on July 24, 2006, 5:53 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have a PIX-501 just installed. Inside are two servers and an Intranet
for employees. The people on the inside can no longer reach the servers
using their DNS-named IP addresses. This would mean that they are doing
an outgoing HTTP or HTTPS connection back to a server that is inside
the PIX. However, since the PIX allows outbound HTTP and HTTPS
connections, and since it allows inbound connections to the servers, it
seems like this should work. Any comments?


Posted by Walter Roberson on July 24, 2006, 7:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>I have a PIX-501 just installed. Inside are two servers and an Intranet
>for employees. The people on the inside can no longer reach the servers
>using their DNS-named IP addresses. This would mean that they are doing
>an outgoing HTTP or HTTPS connection back to a server that is inside
>the PIX. However, since the PIX allows outbound HTTP and HTTPS
>connections, and since it allows inbound connections to the servers, it
>seems like this should work.

You probably won't be able to get it to work by IP address.

Since they are accessing using DNS anyhow, use the 'dns' keyword
on the 'static' command that defines the static translation for
the server. If your DNS server is external, then the dns keyword
will trigger translation of the received IP into the internal version.
If your DNS server is external, then along with the 'dns' keyword,
you will need to change your DNS server to return the -internal- IP
address [presuming it is on the same interface]: then when external
people ask your internal server for the IP address, the internal
server hands out the internal IP and the dns keyword tells the PIX
to translate the internal IP to the public IP as the dns packet transits
the PIX to outside.

Posted by Spack on July 25, 2006, 7:02 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Chris.Fox@alicit.com wrote on 24 Jul 2006 14:53:08 -0700:

> I have a PIX-501 just installed. Inside are two servers and an Intranet
> for employees. The people on the inside can no longer reach the servers
> using their DNS-named IP addresses. This would mean that they are doing
> an outgoing HTTP or HTTPS connection back to a server that is inside
> the PIX. However, since the PIX allows outbound HTTP and HTTPS
> connections, and since it allows inbound connections to the servers, it
> seems like this should work. Any comments?

It's a security feature - packets are never allowed to be passed back to the
same interface they arrived on. There is nothing wrong with the PIX - it's
how it's supposed to work.

Walter has already suggested one solution by having a separate DNS config
for your internal users, but there is a simpler way - look into the "alias"
command. This enables the PIX to change the returned IP addresses in DNS
packets to internal users with the mapped internal IP address, allowing you
to continue to use the public IPs in the DNS setup and still have your
internal users get to the servers. However, this assumes that the DNS
servers are not on your internal PIX interface.

If you can provide more details someone might be able to help suggestion
config changes.

Dan



Similar ThreadsPosted
Pix 501 to Pix 501 VPN Issue December 28, 2005, 1:06 pm
Sonicwall VPN Issue August 1, 2004, 11:46 pm
Network issue March 11, 2005, 7:18 am
Connection Issue September 15, 2005, 10:11 am
Pix Firewall Issue November 20, 2005, 9:31 pm
Web server issue May 6, 2006, 12:46 am
FW1 NGX R62 on IP530 issue January 8, 2007, 4:53 am
NLB Firewall Issue? June 1, 2007, 11:56 am
Re: Router Issue. October 16, 2007, 5:18 am
Re: Router Issue. October 17, 2007, 7:20 am

The site map in XML format XML site map

Contact Us | Privacy Policy