<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX not allowing traffic from Inside Interface to device in  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205991#M861533</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the response.  I implemented the static tranlsation as published, but unfortunantly it did not resolve the issue.  We still cannot get from 172.16.43.144 to 192.168.155.6. &lt;/P&gt;&lt;P&gt; This is a very strange problem.  I ran "capture" on the inside interface, and was able to see frames on that interface destined for 192.168.155.6.  I then placed the capture on the DMZ interface, and you never see the frames.  I am not sure why the FW is blocking...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Mar 2009 18:21:19 GMT</pubDate>
    <dc:creator>Kevin Melton</dc:creator>
    <dc:date>2009-03-27T18:21:19Z</dc:date>
    <item>
      <title>PIX not allowing traffic from Inside Interface to device in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205989#M861525</link>
      <description>&lt;P&gt;I am working at a client site. We have an issue where a PIX Firewall is not allowing access to a device in a DMZ network from devices on the Inside interface.&lt;/P&gt;&lt;P&gt;Here are the security levels of the interfaces:&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 DMZ security50&lt;/P&gt;&lt;P&gt;Network 172.16.43.0 is off of the inside interface.  Network 192.168.155.0 is the DMZ (DMZ interface address is 192.168.155.1).&lt;/P&gt;&lt;P&gt;I have ran captures this morning and determined that 1) traffic destined for a device in the 192.168.155.0 network makes it to the inside interface and 2) traffic seen on the inside interface for this device never makes it into the DMZ.&lt;/P&gt;&lt;P&gt;There is not an ACL in place on the DMZ interface, and right now I cannot determine why the Firewall is blocking this traffic.&lt;/P&gt;&lt;P&gt;I am going to include the running configuraton of this.&lt;/P&gt;&lt;P&gt;The device we are trying to connect to is 192.168.155.6.  The device we are trying to connect from is 172.16.43.144.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205989#M861525</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2019-03-11T15:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not allowing traffic from Inside Interface to device in</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205990#M861527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;static (inside,DMZ) 172.16.43.0 172.16.43.0 netmask 255.255.255.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Mar 2009 17:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205990#M861527</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-03-27T17:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not allowing traffic from Inside Interface to device in</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205991#M861533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the response.  I implemented the static tranlsation as published, but unfortunantly it did not resolve the issue.  We still cannot get from 172.16.43.144 to 192.168.155.6. &lt;/P&gt;&lt;P&gt; This is a very strange problem.  I ran "capture" on the inside interface, and was able to see frames on that interface destined for 192.168.155.6.  I then placed the capture on the DMZ interface, and you never see the frames.  I am not sure why the FW is blocking...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Mar 2009 18:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205991#M861533</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2009-03-27T18:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not allowing traffic from Inside Interface to device in</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205992#M861537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please add a static route for dmz network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route dmz 192.168.155.0 255.255.255.0 nexthop (ip add) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Mar 2009 00:19:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205992#M861537</guid>
      <dc:creator>javzone</dc:creator>
      <dc:date>2009-03-28T00:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not allowing traffic from Inside Interface to device in</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205993#M861540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;should the ip address for next hop (ip add) be the address of the device in the dmz?  or the IP address of the dmz interface on the PIX?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Mar 2009 14:49:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205993#M861540</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2009-03-31T14:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not allowing traffic from Inside Interface to device in</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205994#M861544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;192.168.155.0 is directly connected, you do not need a route to it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Mar 2009 14:59:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205994#M861544</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-03-31T14:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not allowing traffic from Inside Interface to device in</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205995#M861547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are exactly correct.  It displayed the following when I tried to add the route the other gentleman suggested:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ODEC-RS-FW(config)# route dmz 192.168.155.0 255.255.255.0 192.168.155.6&lt;/P&gt;&lt;P&gt;Route already exists&lt;/P&gt;&lt;P&gt;ODEC-RS-FW(config)# route dmz 192.168.155.0 255.255.255.0 192.168.155.1&lt;/P&gt;&lt;P&gt;Route already exists&lt;/P&gt;&lt;P&gt;ODEC-RS-FW(config)# sho route&lt;/P&gt;&lt;P&gt;        outside 0.0.0.0 0.0.0.0 24.154.93.1 1 OTHER static&lt;/P&gt;&lt;P&gt;        outside 24.154.93.0 255.255.255.0 24.154.93.12 1 CONNECT static&lt;/P&gt;&lt;P&gt;        inside 172.16.43.0 255.255.255.0 172.16.143.2 1 OTHER static&lt;/P&gt;&lt;P&gt;        inside 172.16.143.0 255.255.255.252 172.16.143.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ 192.168.100.7 255.255.255.255 192.168.155.6 1 OTHER static&lt;/P&gt;&lt;P&gt;        DMZ 192.168.155.0 255.255.255.0 192.168.155.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;ODEC-RS-FW(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acomiskey - -  do you have any other recommendations as to what to configure next.  We are really stuck on this issue...&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Mar 2009 15:03:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205995#M861547</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2009-03-31T15:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not allowing traffic from Inside Interface to device in</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205996#M861552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please  post your new configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take this line out, you don't need it...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list DMZ_nat0_outbound permit ip 192.168.155.0 255.255.255.0 172.16.43.0 255.255.255.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Mar 2009 15:15:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205996#M861552</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-03-31T15:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not allowing traffic from Inside Interface to device in</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205997#M861557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;acomiskey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At present it seems that negating the ACL statement that you recommended may have resolved the problem.  I need to confirm this by the local users on that site.&lt;/P&gt;&lt;P&gt;I will update you once this is confirmed and mark post "resolved issue"&lt;/P&gt;&lt;P&gt;Thanks for your guidance with this!&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Mar 2009 15:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205997#M861557</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2009-03-31T15:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: PIX not allowing traffic from Inside Interface to device in</title>
      <link>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205998#M861560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason you don't need that nat 0 on the dmz interface is because you already had one defined on the inside interface for the traffic between .43 and .155. So you have 2 options here...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;access-list nonat extended permit 172.16.43.0 255.255.255.0 192.168.155.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR another way to accomplish the same thing...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,DMZ) 172.16.43.0 172.16.43.0 netmask 255.255.255.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Mar 2009 16:08:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-not-allowing-traffic-from-inside-interface-to-device-in-dmz/m-p/1205998#M861560</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-03-31T16:08:24Z</dc:date>
    </item>
  </channel>
</rss>

