04-09-2010 06:42 AM - edited 03-11-2019 10:31 AM
Hi,
I have Cisco PIX 515E With Cisco PIX Security Appliance Software Version 7.0(6).
We are using three interfaces. One outside, second WEB(for web server) & third DB(for database server)
We have published our web server and so available from public network.
Now, I want to access my website(web server) from inside network(servers connected to WEB interface) with public IP address. But it is not working.
When I try from inside of the network, the packet is handled by the default route and sent onto the outside interface. At that point, the packet disappears because the PIX does not turn the packet around and send it back inside. In fact, I'm not even sure that the NAT
rules come into play in this scenario.
So, is it possible to hit external IP of my web server from internally?
If yes than how?
Regards,
Anil Oza
05-06-2010 11:56 PM
05-07-2010 02:56 AM
Hi Anil,
As Ashu advised earlier, you would need to upgrade the PIX to at least version 7.2.1 for the "same-security-traffic permit intra-interface" command to work for clear text traffic (as in your case).
Please upgrade the PIX to version 7.2.1 (I would recommend 7.2.4 as Ashu's advise) and what you are trying to achieve will work.
05-07-2010 03:11 AM
Thanks to both of you for help.
last qst... what is a clear text traffic. Means it will work for only http not for https.
05-07-2010 03:15 AM
Clear text means it is not encrypted through IPSec VPN tunnel.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide