09-09-2003 06:52 AM - edited 02-20-2020 10:58 PM
Hi,
I am having an issue with PIX 6.3(3) creating a static inbound tunnel to web servers running NLBS/WLBS in both unicast and multicast mode. Has anyone been able to get this working?
Thanks
09-09-2003 06:35 PM
It should be transparent to the PIX which isn't the case for the switch handling NLB traffics. But this is another issue.
Regards
Ben
09-11-2003 12:20 AM
First, is load balancing working well?
09-11-2003 05:36 AM
Yes. I've used it well with ISA without any problem (of course because of the type of firewall that ISA is) but the PIX refuses to work. Can't connect through the inbound tunnel to the load balanced address.
09-11-2003 06:13 AM
We have implemented it in customer site, ISA/NLB accessed over a PIX, as i said earlier, it was transparent to the PIX. The PIX never knows about NLB stuffs.
Regards
Ben
09-11-2003 06:35 AM
I understand how it would work behind an ISA firewall.
What I'm talking about is running NLBS directly behind a PIX - because the machines reply with different MACs? Am I wrong?
09-11-2003 11:05 AM
Hi,
The PIX shouldn't take care of which MAC address the packet is coming from. It takes care about IP/ICMP/TCP/UDP. For example, the packet may come from 2 or more differents inside routers before reaching the PIX which is the same case you have except you have differents hosts instead of routers.
Ben
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide