<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515 NAT for  Inside Remote Network Problem? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-nat-for-inside-remote-network-problem/m-p/1351879#M751254</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Only thing I can think of is that the 192.168.3.x web server doesn't have a default route pointing back towards the inside interface of the PIX.&amp;nbsp; It must have a route for the 192.168.1.x network cause you can ping it from the PIX itself, but traffic coming from the Internet is going to have a public IP source address, and so the web server will need a default route that get's that traffic back to the PIX.&amp;nbsp; Check that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Glenn.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Jan 2010 23:21:40 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2010-01-11T23:21:40Z</dc:date>
    <item>
      <title>PIX 515 NAT for  Inside Remote Network Problem?</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-nat-for-inside-remote-network-problem/m-p/1351878#M751253</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 515 with 2 interaces, Using INSIDE 192.168.1.0 Network and OUTSIDE 206.207.208.0 Network.&lt;/P&gt;&lt;P&gt;I have currently web servers mapped for the External IP to the Inside: 206.207.208.15 to the 192.168.1.15 Address.NAT Translation is working fine for 192.168.1.0 network.&lt;/P&gt;&lt;P&gt;Now I have a WEBSERVER on a subnet 192.168.3.0, which I need to NAT from this PIX 515.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**************************************************************************************************&lt;/P&gt;&lt;P&gt;name 192.168.3.48 WEBSERVER48&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 206.207.208.16 eq www&lt;/P&gt;&lt;P&gt;pdm location 192.168.3.48 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.3.48 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 206.207.208.16 192.168.3.48 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;route inside 192.168.3.48 255.255.255.255 192.168.1.1 1&lt;/P&gt;&lt;P&gt;**************************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above NAT pointing to the remote network is not working for this WEBSERVER48, I see their is a delay and after that the browser times out. I can ping from the PIX 515 (Inside IP 192.168.1.50) to the 192.168.3.48 via the 192.168.1.1 Default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.3.0 Network is connected through the IPVPN(MPLS Network),with 10MB guaranteed bandwidth. There are no routing issues from 192.168.1.0 for reaching to the 192.168.3.0 network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise options to troubleshoot this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Shan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:55:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-nat-for-inside-remote-network-problem/m-p/1351878#M751253</guid>
      <dc:creator>shanahmad</dc:creator>
      <dc:date>2019-03-11T16:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 NAT for  Inside Remote Network Problem?</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-nat-for-inside-remote-network-problem/m-p/1351879#M751254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Only thing I can think of is that the 192.168.3.x web server doesn't have a default route pointing back towards the inside interface of the PIX.&amp;nbsp; It must have a route for the 192.168.1.x network cause you can ping it from the PIX itself, but traffic coming from the Internet is going to have a public IP source address, and so the web server will need a default route that get's that traffic back to the PIX.&amp;nbsp; Check that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Glenn.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 23:21:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-nat-for-inside-remote-network-problem/m-p/1351879#M751254</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2010-01-11T23:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 NAT for  Inside Remote Network Problem?</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-nat-for-inside-remote-network-problem/m-p/1351880#M751257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; i have two questions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;whether the web server is configured to listen any specific subnets?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you able browse it from your internal network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 04:21:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-nat-for-inside-remote-network-problem/m-p/1351880#M751257</guid>
      <dc:creator>Dileep Sivadas Padmini</dc:creator>
      <dc:date>2010-01-12T04:21:43Z</dc:date>
    </item>
  </channel>
</rss>

