PIX 515E running 6.2(2)
I have 2 hosts on a dmz subnet of 10.250.1.0/24
this network connects directly to a firewall interface.
i have an internal network of 10.1.0.0/16
this net is separated by routers
hosts behind the internal network can ping 10.250.1.11 but they cannot ping 10.250.1.10
I have a static NAT for both hosts as they are accessible from the public. the public can get to both servers.
i can ping both from the firewall and show separate arp entries for both servers
unfortunately the guys on the internal have stopped their pings, however, debug icmp trace shows that
whenever they try to ping 10.250.1.11, I see a reply with no problems.
10.1.3.14 > CYBER-TEST echo
CYBER-TEST > 10.1.3.14 echo-reply
When i try 10.250.1.10, i see that the packet wants to go to the outside firewall interface
10.1.3.14 > 203.19.117.1 > CYBER_TEST
instead of following the proper route thru to the DMZ.
can anyone explain why this would be happening?
cheers
my relevant config is attached