<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Firewall Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029792#M941234</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes outside server has the route towards it. I am also getting hitcount on my outside firewall access-list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see the snapshot of pkt tracer from outside interface to dmz. it is successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Mar 2008 23:10:15 GMT</pubDate>
    <dc:creator>wasiimcisco</dc:creator>
    <dc:date>2008-03-10T23:10:15Z</dc:date>
    <item>
      <title>PIX Firewall Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029790#M941231</link>
      <description>&lt;P&gt;I am again having strange problem. I have two servers in dmz. I want one server to go to internet and also communicate with one of the server located on outside with local ip address 172.28.92.72&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ASDM is showing me packet tracer successfuly without any problem. But when i try to ping from server on dmz to server located on outside i got the following error &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination net unreachable.&lt;/P&gt;&lt;P&gt;Destination net unreachable.&lt;/P&gt;&lt;P&gt;Destination net unreachable.&lt;/P&gt;&lt;P&gt;Destination net unreachable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured the same setting as for the server 2 with ip addresss 172.28.92.68. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i want 172.28.92.72 to have static for internet but to communicate with outside server use same ip 172.28.92.72&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit ip host x.74.112.153 host 172.28.92.72 &lt;/P&gt;&lt;P&gt;access-list nonat extended permit ip host 172.28.92.72 host x.74.112.153 &lt;/P&gt;&lt;P&gt;static (edn,outside) x.223.188.39 172.28.92.72 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;telnet 172.28.92.72 255.255.255.255 edn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TDC-INT-525-01# sh run | in 172.28.92.68&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit ip x.223.188.0 255.255.255.0 host 172.28.92.68 &lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit ip host x.74.112.153 host 172.28.92.68 &lt;/P&gt;&lt;P&gt;access-list nonat extended permit ip host 172.28.92.68 x.223.188.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list nonat extended permit ip host 172.28.92.68 host x.74.112.153&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;nat (edn) 0 access-list nonat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please help me out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:14:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029790#M941231</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2019-03-11T12:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Firewall Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029791#M941233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you checked whether the server on the outside knows how to route traffic back to 172.28.92.72? If it does can you look at the packet trace on the outside interface to see if you see response from the Server on the outside coming in?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 23:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029791#M941233</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2008-03-10T23:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Firewall Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029792#M941234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes outside server has the route towards it. I am also getting hitcount on my outside firewall access-list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see the snapshot of pkt tracer from outside interface to dmz. it is successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 23:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029792#M941234</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-03-10T23:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Firewall Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029793#M941237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting. Have you tried removing the static and check whether that made any difference. If not can you do a sniffer capture on the DMZ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 23:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029793#M941237</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2008-03-10T23:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Firewall Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029794#M941238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if i removed the static it works as it is working with 172.28.92.68. But my requirement is to use static to use Internet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;right now i have removed teh nonat for 172.28.92.72 and using only static for Internet and outside server is accessing it via static ip addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but dont know what is wrong with the static and nonat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet tracer is showing full success but when try to trace and ping&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;destination network unreachable. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only nonat is working or either static is working not both at the same time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 00:16:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029794#M941238</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-03-11T00:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Firewall Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029795#M941239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad it works!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you do the static at port level for Internet access and that may be a workaround for you to get both working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Moreover, can you use a different name for no-nat access list and that should be different from no-nat access list name for the inside interface. It really shouldn't matter but with all the caveats it's worth a try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 00:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-problem/m-p/1029795#M941239</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2008-03-11T00:50:42Z</dc:date>
    </item>
  </channel>
</rss>

