- Posts: 198
- Thank you received: 1
NAT issue in PIX
17 years 1 month ago #23593
by Dove
Dove
Replied by Dove on topic Re: NAT issue in PIX
Hi All
Thakns for your replies.
The actual requirement is Server is placed in our office and our clients from outside is trying to access this server. It was accessible very long back. Now again they are trying to access this server but now they are unsuccessful.
There is one more server for same client in our office with same IP subnet which also having the same kind of ACL & static NAT and which is working fine.
Please let me know if you need any more information. As its very strange issue I dont how to fix. Please help me on this.
Thakns for your replies.
The actual requirement is Server is placed in our office and our clients from outside is trying to access this server. It was accessible very long back. Now again they are trying to access this server but now they are unsuccessful.
There is one more server for same client in our office with same IP subnet which also having the same kind of ACL & static NAT and which is working fine.
Please let me know if you need any more information. As its very strange issue I dont how to fix. Please help me on this.
Dove
17 years 1 month ago #23606
by Smurf
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Replied by Smurf on topic Re: NAT issue in PIX
Its not something daft like the default gateway on the server ?
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
17 years 1 month ago #23616
by Dove
Dove
Replied by Dove on topic Re: NAT issue in PIX
Hi Smurf,
Sorry I dont understan what do mean by default gateway here... the problem here is the particular static NAT is not happening.
Sorry I dont understan what do mean by default gateway here... the problem here is the particular static NAT is not happening.
Dove
17 years 1 month ago #23617
by Smurf
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Replied by Smurf on topic Re: NAT issue in PIX
Hi Dove,
I was just thinking, if this has been working in the past and no changes have been made to the Pix to break this, then it could be a miss-configured default gateway on the server. Usually the NAT working on the way out to NAT the internal IP Address with an external Public IP ADdress. When its coming inwards through a Static, the original source address is maintained therefore the server needs to be able to route to the public address back through the Pix.
I was just thinking, if this has been working in the past and no changes have been made to the Pix to break this, then it could be a miss-configured default gateway on the server. Usually the NAT working on the way out to NAT the internal IP Address with an external Public IP ADdress. When its coming inwards through a Static, the original source address is maintained therefore the server needs to be able to route to the public address back through the Pix.
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
17 years 1 month ago #23618
by Dove
Dove
Replied by Dove on topic Re: NAT issue in PIX
Ok, If its default gateway is misconfigured then it will not be pingable from PIX (if I am not wrong)...but from PIX I can ping the server with its Native / local IP.
Dove
17 years 1 month ago #23620
by Smurf
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Replied by Smurf on topic Re: NAT issue in PIX
That would be true if its not on the same subnet as the pix interface. Your post doesn't give any details of how its configured, without that i'm affraid i am unable to suggest anything further.
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Time to create page: 0.134 seconds