<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dmz issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714251#M965849</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;S    0.0.0.0 0.0.0.0 [1/0] via 12.x.x.1, outside&lt;/P&gt;&lt;P&gt;C    12.x.x.0 255.255.255.128 is directly connected, outside&lt;/P&gt;&lt;P&gt;S    192.168.0.0 255.255.255.0 [1/0] via 192.168.252.3, inside&lt;/P&gt;&lt;P&gt;C    192.168.8.0 255.255.255.0 is directly connected, dmz&lt;/P&gt;&lt;P&gt;C    192.168.252.0 255.255.255.0 is directly connected, inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Aug 2007 19:41:48 GMT</pubDate>
    <dc:creator>bma</dc:creator>
    <dc:date>2007-08-03T19:41:48Z</dc:date>
    <item>
      <title>dmz issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714245#M965837</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  We have PIX version 7.0. Netscaler in the dmz, and virtual server ip is the 192.168.8.98 (dmz network 192.168.8.0). inside web server is 192.168.0.250 setup with virtual server. If I setup a static (dmz,outside) 12.x.x.x 192.168.8.98 netmask 255.255.255.255 0 0 and access-list permit www access, when &lt;A class="jive-link-custom" href="http://12.x.x.x" target="_blank"&gt;http://12.x.x.x&lt;/A&gt; to access server get following message after build connection:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No route to 67.122.x.x from 192.168.0.250&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is message from syslog: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2007-08-03 16:02:01 UTC	Local0.Info	192.168.x.1	Aug 03 2007 08:50:53 : %PIX-6-302013: Built inbound TCP connection -1599250756 for vip-extranet:67.122.x.x/62523 (67.122.x.x/62523) to inside:192.168.0.250/8080 (192.168.0.250/8080)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2007-08-03 16:02:01 UTC	Local0.Info	192.168.x.1	Aug 03 2007 08:50:53 : %PIX-6-110001: No route to 67.122.x.x from 192.168.0.250&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2007-08-03 16:02:01 UTC	Local0.Info	192.168.x.1	Aug 03 2007 08:50:53 : %PIX-6-302014: Teardown TCP connection -1599251913 for vip-extranet:67.122.x.x/62115 to inside:192.168.0.250/8080 duration 0:00:30 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't sure it is routing issue and I ping from 67.122.x.x to 12.x.x.x is fine. please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ben&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:53:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714245#M965837</guid>
      <dc:creator>bma</dc:creator>
      <dc:date>2019-03-11T10:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: dmz issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714246#M965838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ben &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you send a copy of your pix config if possible. If not could you send the NAT statements, intreface addresses and routing table. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 18:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714246#M965838</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-08-03T18:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: dmz issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714247#M965839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;2007-08-03 16:02:01 UTC Local0.Info 192.168.x.1 Aug 03 2007 08:50:53 : %PIX-6-302013: Built inbound TCP connection -1599250756 for vip-extranet:67.122.x.x/62523 (67.122.x.x/62523) to inside:192.168.0.250/8080 (192.168.0.250/8080) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;are you trying to acces your site using &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://12.x.x.x:8080" target="_blank"&gt;http://12.x.x.x:8080&lt;/A&gt; or &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://12.x.x.x" target="_blank"&gt;http://12.x.x.x&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://12.x.x.x:8080" target="_blank"&gt;http://12.x.x.x:8080&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is your netscaler doing Port re-direction from http ( 80 ) to 8080 ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If no then then you have do it either on AS or Netscaler&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 18:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714247#M965839</guid>
      <dc:creator>anandramapathy</dc:creator>
      <dc:date>2007-08-03T18:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: dmz issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714248#M965842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is related lines in the static lines&lt;/P&gt;&lt;P&gt;and show route:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (dmz) 1 192.168.8.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 192.168.0.0 192.168.0.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C    192.168.8.0 255.255.255.0 is directly connected, vip-extranet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to get routing table? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no static setup for the virtual server ip setup, but don't sure how to setup it for virtual server ip? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 18:40:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714248#M965842</guid>
      <dc:creator>bma</dc:creator>
      <dc:date>2007-08-03T18:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: dmz issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714249#M965845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I try both, all get same messages. &lt;/P&gt;&lt;P&gt;netscaler virture server can do re-direction from 80 to 8080. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 18:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714249#M965845</guid>
      <dc:creator>bma</dc:creator>
      <dc:date>2007-08-03T18:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: dmz issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714250#M965847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ben &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;routing table = "sh route"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 19:22:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714250#M965847</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-08-03T19:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: dmz issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714251#M965849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;S    0.0.0.0 0.0.0.0 [1/0] via 12.x.x.1, outside&lt;/P&gt;&lt;P&gt;C    12.x.x.0 255.255.255.128 is directly connected, outside&lt;/P&gt;&lt;P&gt;S    192.168.0.0 255.255.255.0 [1/0] via 192.168.252.3, inside&lt;/P&gt;&lt;P&gt;C    192.168.8.0 255.255.255.0 is directly connected, dmz&lt;/P&gt;&lt;P&gt;C    192.168.252.0 255.255.255.0 is directly connected, inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 19:41:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714251#M965849</guid>
      <dc:creator>bma</dc:creator>
      <dc:date>2007-08-03T19:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: dmz issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714252#M965851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Do you have any idea about Netscaler virtual server ip and phiscal server ip can be on different subnet?  My issue is virtual ip and phiscal server ip in different subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;en&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 20:20:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-issues/m-p/714252#M965851</guid>
      <dc:creator>bma</dc:creator>
      <dc:date>2007-08-03T20:20:30Z</dc:date>
    </item>
  </channel>
</rss>

