<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix Loopback?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939329#M917662</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may want to look into hairpining with static nat, take a look at this link mid way down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968d1.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968d1.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;-Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Jun 2008 21:17:57 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2008-06-25T21:17:57Z</dc:date>
    <item>
      <title>Pix Loopback??</title>
      <link>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939328#M917652</link>
      <description>&lt;P&gt;I have a 515E running 7.2(2) with two interfaces.  This firewall is the default gateway for all internal systems.  I have an inside host with a static translation... ACL allows access to this host from the Internet.  What I need, if possible, is to have *internal* clients access the host using it's public address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;^scratches head^&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;JD&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939328#M917652</guid>
      <dc:creator>jdlampard</dc:creator>
      <dc:date>2019-03-11T13:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Loopback??</title>
      <link>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939329#M917662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may want to look into hairpining with static nat, take a look at this link mid way down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968d1.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968d1.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;-Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jun 2008 21:17:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939329#M917662</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-06-25T21:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Loopback??</title>
      <link>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939330#M917673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hairpinning provides the necessary access.  Thanks for your prompt response, Jorge!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-JD&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jun 2008 01:19:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939330#M917673</guid>
      <dc:creator>jdlampard</dc:creator>
      <dc:date>2008-06-26T01:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Loopback??</title>
      <link>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939331#M917677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jonathan, glad it worked  and thank you for the rating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;-Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jun 2008 01:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939331#M917677</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-06-26T01:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Loopback??</title>
      <link>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939332#M917685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if it would work, but can you setup a static translation from the internal interface to the internal interface and map the internal IP address to the IP?  I tried to enter the command on a production ASA running v7 code and it didn't complain that I was doing a NAT on the same interface.  I haven't tested if it works though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that doesn't work, my suggestion would be to setup the server on a seperate VLAN to the rest of your internal network and change the internal interface to use trunking, that way you should be able to setup NATs from the 'internal' interface and from the 'external' interface with the same IP address to the 'server' interface, and not have to use any other interfaces. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is assuming that you are not using the external IP address of the PIX for the static translation.  If you are using the external interface IP for the translation, I am not sure if it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone else with suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jun 2008 03:21:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939332#M917685</guid>
      <dc:creator>goulin</dc:creator>
      <dc:date>2008-06-26T03:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Loopback??</title>
      <link>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939333#M917691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I appreciate your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed the hairpinning configuration sample in the link that Jorge supplied and it worked exactly as needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All clients, Internet and internal, access the host with the public (NAT) address.  I verified with traceroute and by simply looking in the Pix's log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-JD&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jun 2008 03:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-loopback/m-p/939333#M917691</guid>
      <dc:creator>jdlampard</dc:creator>
      <dc:date>2008-06-26T03:26:28Z</dc:date>
    </item>
  </channel>
</rss>

