<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic pix 515 6.0.1 with 3 interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-6-0-1-with-3-interfaces/m-p/9716#M697877</link>
    <description>&lt;P&gt;i have a DNS server on DMZ, i want inside users to ping DNS server with his public address&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 05:48:45 GMT</pubDate>
    <dc:creator>ytalibi</dc:creator>
    <dc:date>2020-02-21T05:48:45Z</dc:date>
    <item>
      <title>pix 515 6.0.1 with 3 interfaces</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-6-0-1-with-3-interfaces/m-p/9716#M697877</link>
      <description>&lt;P&gt;i have a DNS server on DMZ, i want inside users to ping DNS server with his public address&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:48:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-6-0-1-with-3-interfaces/m-p/9716#M697877</guid>
      <dc:creator>ytalibi</dc:creator>
      <dc:date>2020-02-21T05:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: pix 515 6.0.1 with 3 interfaces</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-6-0-1-with-3-interfaces/m-p/9717#M697888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to do static NAT inside to DMZ and conduit commands required. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2001 13:33:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-6-0-1-with-3-interfaces/m-p/9717#M697888</guid>
      <dc:creator>metin</dc:creator>
      <dc:date>2001-07-10T13:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: pix 515 6.0.1 with 3 interfaces</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-6-0-1-with-3-interfaces/m-p/9718#M697910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your DNS server on the DMZ has a static to the outside, then you are trying to send a packet through the outside interface, then turn back around and come back in the outside interface.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is essentially a redirect, which the ASA (rule engine) of the PIX will not permit.  You should be able to reach the dns server using the private ip address or by domain name if using the alias command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are not using a static for your DNS server, and it is dual-homed, then it should work fine (kind of defeats the purpose of the PIX though).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2001 14:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-6-0-1-with-3-interfaces/m-p/9718#M697910</guid>
      <dc:creator>jekrauss</dc:creator>
      <dc:date>2001-07-10T14:06:03Z</dc:date>
    </item>
  </channel>
</rss>

