<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Accessing a node on the DMZ from an inside interface on the same in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/accessing-a-node-on-the-dmz-from-an-inside-interface-on-the-same/m-p/2162109#M359168</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you want to access the DMZ3 server by using its public or private IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case it's the first one, try to add the "&lt;STRONG&gt;dns&lt;/STRONG&gt;" keywork at the end of the static translation for that server to the outside, it'll enable the DNS doctoring feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case you want to access the server using its private IP from the internal clients, you can configure a self-translation rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static(LAB,DMZ3)&lt;/STRONG&gt; &lt;SERVER&gt; &lt;SERVER&gt;&lt;/SERVER&gt;&lt;/SERVER&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 Apr 2013 16:52:50 GMT</pubDate>
    <dc:creator>jocamare</dc:creator>
    <dc:date>2013-04-01T16:52:50Z</dc:date>
    <item>
      <title>Accessing a node on the DMZ from an inside interface on the same PIX</title>
      <link>https://community.cisco.com/t5/network-security/accessing-a-node-on-the-dmz-from-an-inside-interface-on-the-same/m-p/2162108#M359167</link>
      <description>&lt;P&gt;I have a PIX 515e running version 7.2(4).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 interfaces - DMZ3 (sec lvl 50) and LAB (sec lvl 100) behind the pix. There is also the OUTSIDE interface (sec lvl 0) which connects to the internet.&lt;/P&gt;&lt;P&gt;In DMZ3 I have a webserver - x.x.124.217/24 (host is NATed via static command to public IP)&lt;/P&gt;&lt;P&gt;In LAB I have a server - x.x.1.203/24 (entire range is NATed via NAT/Global statements to public IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The server in LAB needs to access a webserver in DMZ3. From the internet both of these hosts have public addresses that are NATed into the inside addresses. I can reach the webserver from the internet, but not from the LAB interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I have to add a static command so that the LAB host can access the DMZ3 host without accessing the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance would be appriciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/accessing-a-node-on-the-dmz-from-an-inside-interface-on-the-same/m-p/2162108#M359167</guid>
      <dc:creator>dgeorgeadis</dc:creator>
      <dc:date>2019-03-12T01:22:07Z</dc:date>
    </item>
    <item>
      <title>Accessing a node on the DMZ from an inside interface on the same</title>
      <link>https://community.cisco.com/t5/network-security/accessing-a-node-on-the-dmz-from-an-inside-interface-on-the-same/m-p/2162109#M359168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you want to access the DMZ3 server by using its public or private IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case it's the first one, try to add the "&lt;STRONG&gt;dns&lt;/STRONG&gt;" keywork at the end of the static translation for that server to the outside, it'll enable the DNS doctoring feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case you want to access the server using its private IP from the internal clients, you can configure a self-translation rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static(LAB,DMZ3)&lt;/STRONG&gt; &lt;SERVER&gt; &lt;SERVER&gt;&lt;/SERVER&gt;&lt;/SERVER&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Apr 2013 16:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/accessing-a-node-on-the-dmz-from-an-inside-interface-on-the-same/m-p/2162109#M359168</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-04-01T16:52:50Z</dc:date>
    </item>
    <item>
      <title>Accessing a node on the DMZ from an inside interface on the same</title>
      <link>https://community.cisco.com/t5/network-security/accessing-a-node-on-the-dmz-from-an-inside-interface-on-the-same/m-p/2162110#M359169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried this and so far no luck:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (LAB,DMZ3) x.x.1.203 x.x.1.203 netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see in the PIX log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apr 01 2013 14:10:07: %PIX-6-302013: Built outbound TCP connection 96258 for outside:x.x.196.217/443 (x.x.196.217/443) to LAB:x.x.1.203/49314 (x.x.196.222/1032)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where &lt;SPAN style="font-size: 10pt;"&gt;x.x.196.217 = the static NATed address of the web server and &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;x.x.196.222 = the global NATed address of x.x.1.203&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP addresses appear to get translated correctly and I can see the ACLs are incrementing when I attempt to connect but I don't think it is getting through the PIX.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Apr 2013 19:17:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/accessing-a-node-on-the-dmz-from-an-inside-interface-on-the-same/m-p/2162110#M359169</guid>
      <dc:creator>dgeorgeadis</dc:creator>
      <dc:date>2013-04-01T19:17:57Z</dc:date>
    </item>
    <item>
      <title>Accessing a node on the DMZ from an inside interface on the same</title>
      <link>https://community.cisco.com/t5/network-security/accessing-a-node-on-the-dmz-from-an-inside-interface-on-the-same/m-p/2162111#M359170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apologies for the late reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please be very specific on how you want to access the server and from where.&lt;/P&gt;&lt;P&gt;Once that is clarified, the answer will be easy to get. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 00:04:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/accessing-a-node-on-the-dmz-from-an-inside-interface-on-the-same/m-p/2162111#M359170</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-04-03T00:04:56Z</dc:date>
    </item>
  </channel>
</rss>

