<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: firewall not passing server traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-not-passing-server-traffic/m-p/1262323#M763793</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for highlighting, i will get the gateway details for this server to probe from that angle.( this server is hosted in dmz zone &amp;amp; is accessible from withing lan segment as well).&lt;/P&gt;&lt;P&gt;i havent been able to get the last suggestion you made about PAT with local IP.Can you please elaborate.&lt;/P&gt;&lt;P&gt;Appreciate your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 07 Nov 2009 15:14:51 GMT</pubDate>
    <dc:creator>suthomas1</dc:creator>
    <dc:date>2009-11-07T15:14:51Z</dc:date>
    <item>
      <title>firewall not passing server traffic</title>
      <link>https://community.cisco.com/t5/network-security/firewall-not-passing-server-traffic/m-p/1262321#M763782</link>
      <description>&lt;P&gt;Referring to the attached diagram.(sorry if the diagram is not too neat, had to sketch in a hurry).&lt;/P&gt;&lt;P&gt;There are 2 different internet lines being used at different sites.&lt;/P&gt;&lt;P&gt;All internet traffic from Layer3switch 2 uses that internet link. &amp;amp; internet 1 is used for all internet&lt;/P&gt;&lt;P&gt;traffic from Layer3 sw1 segment. &lt;/P&gt;&lt;P&gt;There is a server hosting a site on the right hand side , which is well accessible via its internet &lt;/P&gt;&lt;P&gt;link. This now needs to be accessible via the internet 1 ip segment.&lt;/P&gt;&lt;P&gt;after the setup of doing required nat on fw1 &amp;amp; rules are put in on fw2 alongwith access on FW 3 for this&lt;/P&gt;&lt;P&gt;to be used via internet 1, it cant be accessed. We arent using dns resolution.It is a simple IP over http.&lt;/P&gt;&lt;P&gt;As i checked, the traffic for this comes via internet 1 in to the fw1 &amp;amp; fw 2, but somehow it doesnt &lt;/P&gt;&lt;P&gt;seem to come on to FW3(off which this server resides). Routing is fine across these two sections as i can &lt;/P&gt;&lt;P&gt;reach other things via ping across these two sections.&lt;/P&gt;&lt;P&gt;Any advise would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:36:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-not-passing-server-traffic/m-p/1262321#M763782</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-11T16:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: firewall not passing server traffic</title>
      <link>https://community.cisco.com/t5/network-security/firewall-not-passing-server-traffic/m-p/1262322#M763790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There's alot of details here that might be needed to troubleshoot this issue... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But here's a basic issue that you should address:  A device can only generally use 1 default gateway at a time. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now that's not true in some situations, but it might be the issue here.  Your 'server' is already configured to access the internet via one path.  Now your trying to access it via a different path.  The traffic will get to the server, but the server may only have 1 default gateway configured.  So the traffic goes back out that gateway which is a different path then the way the request came in. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can create asymmetric data paths, which firewalls do not like at all. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One solution would be to PAT the incoming traffic from one of the internet connections to a local LAN IP, if the traffic is destined for the server.  That would enable routing and everything to work correctly.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 20:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-not-passing-server-traffic/m-p/1262322#M763790</guid>
      <dc:creator>cmcbride</dc:creator>
      <dc:date>2009-11-06T20:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: firewall not passing server traffic</title>
      <link>https://community.cisco.com/t5/network-security/firewall-not-passing-server-traffic/m-p/1262323#M763793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for highlighting, i will get the gateway details for this server to probe from that angle.( this server is hosted in dmz zone &amp;amp; is accessible from withing lan segment as well).&lt;/P&gt;&lt;P&gt;i havent been able to get the last suggestion you made about PAT with local IP.Can you please elaborate.&lt;/P&gt;&lt;P&gt;Appreciate your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Nov 2009 15:14:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-not-passing-server-traffic/m-p/1262323#M763793</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2009-11-07T15:14:51Z</dc:date>
    </item>
  </channel>
</rss>

