<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't connect inside host in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367190#M307011</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jumora,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I got home - my high hopes were shot down really quickly!&amp;nbsp; Let me tell you what happened:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- First problem was that I am no longer able to telnet into the 1605 router.&amp;nbsp; I'm not prompted for a password; I get an error "Could not open connection to the host on port 23: Connect failed".&amp;nbsp; Tried from another internal machine, with the same result.&amp;nbsp; This is odd, since it worked yesterday when I pulled the "Show" commands for you.&amp;nbsp; I thought it might be a security incident, but I don't see any changes to any of my configs.&amp;nbsp; So I ended up consoling in to the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Next I tried making the change you recommended.&amp;nbsp; The syntax you provided is for a security appliance only I think; it didn't work on the router.&amp;nbsp; So the conversion I came up with is:&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP NAT INSIDE SOURCE STATIC TCP 192.168.1.202 80 INTERFACE ETHERNET0 1701&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Needless to say it didn't work.&amp;nbsp; I eventually get a timeout from the client attempting to make the connection from outside.&amp;nbsp; Does that syntax look correct to you?&amp;nbsp; Or am I missing something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Final issue:&amp;nbsp; I thought I would go ahead and clean up NAT entries from the PIX.&amp;nbsp; I removed 2 entries:&lt;/P&gt;&lt;P&gt;- global (outside) 1 interface&lt;/P&gt;&lt;P&gt;- nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;After I did so, I lost internet connectivity.&amp;nbsp; Is there something else I need to do first?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for so many issues.&amp;nbsp; I just want to provide as much information as I can.&amp;nbsp; Please let me know what I'm missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Dec 2013 00:06:13 GMT</pubDate>
    <dc:creator>BarryJoseph</dc:creator>
    <dc:date>2013-12-19T00:06:13Z</dc:date>
    <item>
      <title>Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367182#M306994</link>
      <description>&lt;P&gt;I recently installed a Cisco router between my ISP and my PIX 501.&amp;nbsp; Now I am unable to connect to inside servers.&amp;nbsp;&amp;nbsp; I think the problem is my static NAT entries on the PIX.&amp;nbsp; Can anybody help me out?&amp;nbsp; Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Bk&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367182#M306994</guid>
      <dc:creator>BarryJoseph</dc:creator>
      <dc:date>2019-03-12T03:19:04Z</dc:date>
    </item>
    <item>
      <title>Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367183#M306999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;POst a digram, the show tech of the devices involved, show arp and show ip route of the router and show show arp and show route of the PIX. Also please give TCP/IP setttings of the server to understand how you are routing on that server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Dec 2013 06:06:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367183#M306999</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-12-17T06:06:04Z</dc:date>
    </item>
    <item>
      <title>Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367184#M307002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jumora,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response!&amp;nbsp; I will gather the information you have requested and post it later this evening (since I don't currently have access to my LAN from outside).&amp;nbsp; Let me clarify to let you know that prior to the change mentioned above I was able to access everything: my web server, PIX, and SSH to an internal linux host.&amp;nbsp; Now I can't access any of these machines.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You asked about the TCP/IP settings of my server?&amp;nbsp; I have included the IP address of my web server on the attached diagram (although I should have added /24 to indicate the subnet mask).&amp;nbsp; I use static addresses for servers.&amp;nbsp; Please let me know what else you need from the server.&amp;nbsp; I can tell you that I haven't made any changes to any of my endpoint devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the diagram.&amp;nbsp; As I said I will provide the other information you requested later this evening.&amp;nbsp; Also please let me know if you think of anything else I can provide that will be helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;BK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/1/0/171016-HomeLAN.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Dec 2013 16:41:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367184#M307002</guid>
      <dc:creator>BarryJoseph</dc:creator>
      <dc:date>2013-12-17T16:41:06Z</dc:date>
    </item>
    <item>
      <title>Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367185#M307006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just the configurations and show would help me decipherer what is going on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will wait for your posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Dec 2013 17:53:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367185#M307006</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-12-17T17:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367186#M307007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jumora,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached you will find the output of the SHOW commands you have requested.&amp;nbsp; PIX is first, followed by the 1605 router.&amp;nbsp; Please let me know what you think, and if there is additional info I can provide that will make it easier to see what is going on.&amp;nbsp; Also I have hidden the public IP addresses in the router extracts.&amp;nbsp; Let me know if I've removed anything that you need to see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;-Bk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Apparently there's a limit #files to attach.&amp;nbsp; The final Show ARP attachment will be on the way shortly)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 01:00:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367186#M307007</guid>
      <dc:creator>BarryJoseph</dc:creator>
      <dc:date>2013-12-18T01:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367187#M307008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And here's the 1605 Show ARP.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 01:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367187#M307008</guid>
      <dc:creator>BarryJoseph</dc:creator>
      <dc:date>2013-12-18T01:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367188#M307009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You left the static PAT configuration on the PIX without migrating it to the router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 1701 192.168.1.202 www netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The correct line since you are doing NAT on the router would be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface www 192.168.1.202 www netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Access-list is already created on your PIX to allow incoming connections over port TCP/80 through the interface IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI: You should consider to NAT only on one device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 17:20:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367188#M307009</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-12-18T17:20:32Z</dc:date>
    </item>
    <item>
      <title>Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367189#M307010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jumora I can't wait to get home and try this tonight.&amp;nbsp; I figured it was something like that I must have missed.&amp;nbsp; Just wasn't quite sure where to place the entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to be clear I should put "static (inside,outside) tcp interface &lt;STRONG&gt;www&lt;/STRONG&gt; ...." instead of "static (inside,outside) tcp interface &lt;STRONG&gt;1701...&lt;/STRONG&gt;" like I had on the PIX?&amp;nbsp; I still want it coming in over port 1701, but translating to www on the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also in regards to your FYI - I know I have some cleaning up to do.&amp;nbsp; And I will be replacing the PIX with an ASA5505 in the next couple of weeks, so I want to streamline as much as possible.&amp;nbsp; I will remove the NAT entries from the PIX as you have advised.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again - will chime back in tonight to let you know that it worked!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-BK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 18:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367189#M307010</guid>
      <dc:creator>BarryJoseph</dc:creator>
      <dc:date>2013-12-18T18:58:05Z</dc:date>
    </item>
    <item>
      <title>Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367190#M307011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jumora,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I got home - my high hopes were shot down really quickly!&amp;nbsp; Let me tell you what happened:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- First problem was that I am no longer able to telnet into the 1605 router.&amp;nbsp; I'm not prompted for a password; I get an error "Could not open connection to the host on port 23: Connect failed".&amp;nbsp; Tried from another internal machine, with the same result.&amp;nbsp; This is odd, since it worked yesterday when I pulled the "Show" commands for you.&amp;nbsp; I thought it might be a security incident, but I don't see any changes to any of my configs.&amp;nbsp; So I ended up consoling in to the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Next I tried making the change you recommended.&amp;nbsp; The syntax you provided is for a security appliance only I think; it didn't work on the router.&amp;nbsp; So the conversion I came up with is:&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP NAT INSIDE SOURCE STATIC TCP 192.168.1.202 80 INTERFACE ETHERNET0 1701&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Needless to say it didn't work.&amp;nbsp; I eventually get a timeout from the client attempting to make the connection from outside.&amp;nbsp; Does that syntax look correct to you?&amp;nbsp; Or am I missing something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Final issue:&amp;nbsp; I thought I would go ahead and clean up NAT entries from the PIX.&amp;nbsp; I removed 2 entries:&lt;/P&gt;&lt;P&gt;- global (outside) 1 interface&lt;/P&gt;&lt;P&gt;- nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;After I did so, I lost internet connectivity.&amp;nbsp; Is there something else I need to do first?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for so many issues.&amp;nbsp; I just want to provide as much information as I can.&amp;nbsp; Please let me know what I'm missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2013 00:06:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367190#M307011</guid>
      <dc:creator>BarryJoseph</dc:creator>
      <dc:date>2013-12-19T00:06:13Z</dc:date>
    </item>
    <item>
      <title>Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367191#M307012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are at home you can call me or give me your phone number so I can call and maybe help you out on a webex??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2013 00:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367191#M307012</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-12-19T00:53:06Z</dc:date>
    </item>
    <item>
      <title>Can't connect inside host</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367192#M307013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for helping me resolve this!!&amp;nbsp; Will post the final config if anybody wishes to see how jumora made it work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2013 02:40:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-inside-host/m-p/2367192#M307013</guid>
      <dc:creator>BarryJoseph</dc:creator>
      <dc:date>2013-12-19T02:40:45Z</dc:date>
    </item>
  </channel>
</rss>

