Internal hosts cannot browse to a web server on the Demilitarized Zone (DMZ) by name through a PIX Firewall when the Domain Name System (DNS) server is located on the outside.
If internal clients need to access servers off of the DMZ interface of the PIX, and their DNS server is located on the PIX outside interface, then the PIX must do Destination Network Address Translation (DNAT) to the packets from the inside interface to the DMZ.
Here are some possible solutions:
PIX Version 6.2 and Later
If the PIX runs version 6.2 or later, issue this command:
The configuration for DNATting remains same in 7.0 and there is no change in the configuration required.
Users are not able to access the server in DMZ and they get the error "page cannot be displayed"
he problem might be the authentication access level or it could be the NAT configuration for DMZ access issue with the particular user. If you configure the AAA authentication for the user, then check the user rights in the AAA configuration and ACS if you used.
Also verify the ACL permit command and DMZ NAT Configuration have the enough pool of IP address for the translation.
PIX command authorization and expansion of local authentication was introduced in version 6.2 and above. The following documents provides an example of how to set this up on a PIX.
HelloI am using Cisco ASR1006 security gateway. I want to configure IPsec. While configuring multi-tier PKI hierarchy i started wondering about limits: does anyone know what is the limitation of intermediate certificates in chain on this device (x)?RootCA...
Hi, I am able to download user groups which contains 1600 users. In realms I can see one groups which contain 1600 users and successfully downloaded but when I got to policies to create policies I cant see any group under Available Realms. What ...
got redirected here from ISE-PM forum.
Do we have any information/documentation on what ISE versions are compatible with the newly released software versions: iOS 13.x and Android 10.x?
Any input will be highly appreciated.
Hi all, We have problems to change hour my device. We try put command npt in conf t but it´s not permited. And command clock also isn´t permited.Device is ASA5585-SSP-10 and him version is Software Version 9.6(3)9. This ASA have two co...