cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
369
Views
0
Helpful
1
Replies

Forwarding decrypted traffic to host behind PIX DMZ Interface

davelockerby
Level 1
Level 1

I need some direction or documentation links on how to pull-off the following on the PIX firewall:

1. Terminate VPN traffic on PIX (accomplished)

2. Filter decrypted traffic with access-lists on outside interface (accomplished)

3. Forward/Route decrypted taffic to host on DMZ vs. Inside Interface located on same PIX firewall (not sure how to pull this off - does the "connected route" take care of this?)

4. Same host behind PIX DMZ interface needs to forward traffic to host located behind Inside interface on same PIX firewall.

If anyone knows of Cisco documentation links, that can help with the above issues, please post.

Thanks in advance for any and all help!

Cheers.

1 Reply 1

afakhan
Level 4
Level 4

Ans3. If its a L2L, make sure that you have :

nat (dmz) 0 access-list

just like you migh thave :

nat (inside) 0 access-list ACL#

4 - That would require NAT/Global, or static configuration AND acess-list to permit traffic on the PIX.

Thx

Afaq

Review Cisco Networking for a $25 gift card