07-29-2003 05:49 AM - edited 02-20-2020 10:53 PM
We have a Pix 20 (v.6.2(2)). We are trying to configure the pix so that it can pass Windows 2000 authentication (Kerberos) to the inside network from the DMZ. What is the correct and saftest way to do so.
Thanks in advance,
Tou
07-29-2003 07:19 AM
Tou
You will need to set up a static to be able to pass traffic from a lower security level to a higher security level dmz-->inside
static (inside,dmz) 65.xxx.xxx.xxx 10.x.x.x netmask 255.255.255.255
Then I would set up a access list or set of conduits to allow port 750 and any others that MS would like to use for the authentication proccess.. I would also resict it down even further by adding hosts or machines that can talk to the inside network from the DMZ. Never reall felt comfortable allowing the DMZ to talk to a inside interface...
Hope this helps
If there is a better way I am willing to learn :)
07-29-2003 12:49 PM
The static part is working. We just can't pass to the inside (88 and 750 is both open). Any suggestion will be apprecciated.
Thanks,
Tou
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide