<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 520 3 PORT VERSION 6.0(1) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-520-3-port-version-6-0-1/m-p/11716#M697817</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure I completely understand your situation.  However, the behavior of the PIX, using the alias command, has changed in 6.0(1).  In 6.0(1), when you use the alias command to DNS fixup (which you are trying to do), the PIX interface will now proxy-arp for the aliased address.  This is useful if you are using the alias command for destination NAT, but causes DNS fixup to not work.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After you have implemented the alias command, do a show arp and check the MAC address that is associated with your alias address.  You may find that it is one of the PIX interfaces (inside or DMZ).  If so, then enabling sysopt noproxyarp (PIX_interface) will resolve the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 15 Jul 2001 22:39:38 GMT</pubDate>
    <dc:creator>jekrauss</dc:creator>
    <dc:date>2001-07-15T22:39:38Z</dc:date>
    <item>
      <title>PIX 520 3 PORT VERSION 6.0(1)</title>
      <link>https://community.cisco.com/t5/network-security/pix-520-3-port-version-6-0-1/m-p/11715#M697812</link>
      <description>&lt;P&gt;I have a pix 520 with 3 ports, at the DMZ there is a web server,I use the static command to allow outside user access the web server,To allow inside user access the web server correctly,I use the alias command to resolve the domain name to DMZ IP address 192.168.1.253.&lt;/P&gt;&lt;P&gt;The question is when I use alias command to resolve the domain name , it works well,the domain ip address isn't the global ip address 211.99.175.50.&lt;/P&gt;&lt;P&gt;but the inside user cann't access the webserver.&lt;/P&gt;&lt;P&gt;at this time,I ping the 192.168.1.253, the pix nat it to the outside pool,but if I ping the 192.168.1.252 etc. the pix nat it to the DMZ .&lt;/P&gt;&lt;P&gt;If I don't use the alias command, when i ping the 192.168.1.253, the pix nat it to the DMZ,that is correct,but you know ,the inside user cann't access the webserver correctly at this time.&lt;/P&gt;&lt;P&gt;What can I do,I need your help&lt;/P&gt;&lt;P&gt;Duzaidong , Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:48:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-520-3-port-version-6-0-1/m-p/11715#M697812</guid>
      <dc:creator>xiao0809</dc:creator>
      <dc:date>2020-02-21T05:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 520 3 PORT VERSION 6.0(1)</title>
      <link>https://community.cisco.com/t5/network-security/pix-520-3-port-version-6-0-1/m-p/11716#M697817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure I completely understand your situation.  However, the behavior of the PIX, using the alias command, has changed in 6.0(1).  In 6.0(1), when you use the alias command to DNS fixup (which you are trying to do), the PIX interface will now proxy-arp for the aliased address.  This is useful if you are using the alias command for destination NAT, but causes DNS fixup to not work.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After you have implemented the alias command, do a show arp and check the MAC address that is associated with your alias address.  You may find that it is one of the PIX interfaces (inside or DMZ).  If so, then enabling sysopt noproxyarp (PIX_interface) will resolve the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Jul 2001 22:39:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-520-3-port-version-6-0-1/m-p/11716#M697817</guid>
      <dc:creator>jekrauss</dc:creator>
      <dc:date>2001-07-15T22:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 520 3 PORT VERSION 6.0(1)</title>
      <link>https://community.cisco.com/t5/network-security/pix-520-3-port-version-6-0-1/m-p/11717#M697838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According your instruction,I try again but the problem still isn't solved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I ping the domain name, The alias command works well, It can transfer the DNS to DMZ address, But the Nat still direct the traffic to the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2001 04:09:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-520-3-port-version-6-0-1/m-p/11717#M697838</guid>
      <dc:creator>xiao0809</dc:creator>
      <dc:date>2001-07-16T04:09:41Z</dc:date>
    </item>
  </channel>
</rss>

