01-03-2020 03:58 AM - edited 01-03-2020 04:02 AM
I have a internet router with 3 interfaces:
- 1 WAN
- 1 DMZ (192.168.2.1) - servers 192.168.2.10/11/12/15
- 1 LAN (192.168.1.1)
Furthermore I have a Cisco CRS1000v internal router with also 3 interfaces:
- 1 LAN (192.168.1.2) - outside
- 1 SQL (192.168.3.1) - inside - servers 192.168.3.10/11/12
- 1 WIN (192.168.4.1) - inside - servers 192.168.4.10
I have an internet connection from SQL and WIN to the Internet.
I can ping server from SQL to WIN.
I can ping servers from WIN to SQL.
I can ping servers from SQL and WIN to DMZ
But I cannot ping servers from DMZ to WIN or SQL. Tracert stops at 192.168.2.1 (LAN outside interface Cisco)
What am I missing here?
Enclosed you will find my running-config.
Any help would be appreciated and many thanks in advance.
Kind regards,
DB
Solved! Go to Solution.
01-04-2020 03:09 PM
Hi Paul,
Routes seems to be ok. I've enclosed 4 printscreens which will show the correct routes on the CSR and the routes on the pfSense. Two of them are settings of the pfSense gateway to the 192.168.1.2.
Kind regards,
Dennis
01-04-2020 03:36 PM
Hi Paul,
I've got it working thanks to you! The pfSense firewall was blocking traffic from 192.168.24.0 and 192.168.23.0. There was a firewall rule defined on LAN net, but the nat addresses weren't included.
Many thanks for your help and effort. I really appreciate it.
Kind regards,
Dennis
01-04-2020 03:39 PM
Hello
Glad it is now working - It had to be either the routing which you confirmed was okay or a FW rule negating those new subnets we applied on the CSR, anyway all good now - Thanks for the rating and feedback.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide