cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
563
Views
0
Helpful
2
Replies

firewall issue

csc010854800
Level 1
Level 1

i am trying to access server from 192.168.0.28 from 192.168.48.0/24 range on 50000 port but no able to do so.

diagram and config are attached herewith , kindly suggest in any changes needs to be done.

FIREWALL 2:

interface Ethernet0/1
description + + + + Connection 2 LAN (Inside) + + + +
speed 100
duplex full
nameif inside
security-level 100
ip address 192.168.48.254 255.255.255.0
!
interface Ethernet0/2
description + + + + CLIENT + + + +
nameif Client
security-level 90
ip address 192.168.49.250 255.255.255.0


nat (Client) 0 0.0.0.0 0.0.0.0

access-group client_access_in_1 in interface inside
access-group client_access_in in interface Client

access-list inside_access_in_1 extended permit ip any any

access-list client_access_in extended permit ip any any

FIREWALL1:

interface Ethernet0/1
description Server Zone
nameif Server
security-level 100
ip address 192.168.15.253 255.255.240.0
!

interface Ethernet0/3
description Client Zone
nameif client
security-level 90
ip address 192.168.39.253 255.255.240.0

nat (Server) 0 access-list nonatinside
nat (Server) 1 0.0.0.0 0.0.0.0
nat (client) 0 access-list nonatclient
nat (client) 1 0.0.0.0 0.0.0.0

access-group inside_access_in in interface Server
access-group client_access_in in interface client

access-list inside_access_in extended permit ip any any

access-list client_access_in extended permit ip any any

2 Replies 2

varrao
Level 10
Level 10

Hi,

Few things missing here for both the firewall:

FIrewall 2:

nat (inside) 1 0.0.0.0 0.0.0.0

global (outside) 1 interface

Firewall 1:

static (client,server) 192.168.0.28 192.168.0.28

Hope this helps.

Thanks,

Varun

Thanks,
Varun Rao

i have one route for outside world. route outside 0.0.0.0 0.0.0.0 x.x.x.x 1 .in firewall 1 for internet connetivity.

do i need any other routes in my firewall .

also , can u explain why we need these commands

nat (inside) 1 0.0.0.0 0.0.0.0

global (outside) 1 interface

as i have already used

nat (client) 0.0.0.0 0.0.0.0 in my firewall.

also i don't have outside interface configured in my firewall 2.

Review Cisco Networking for a $25 gift card