Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > PIX Firewall problems

Reply
Thread Tools

PIX Firewall problems

 
 
Thys
Guest
Posts: n/a
 
      12-24-2004
Hi all,

I have the current situation :

PIX Firewall with 3 networks attached. LAN (sec100), DMZ(sec50),
Internet(sec0). In the DMZ I have a server that needs to connect to a
server on our LAN. As far as I know you need a static for this. All is
configurerd by a network/firewall engineer. There is also an
access-list that allows Host DMZ -> Host LAN all IP is allowed (for
testing).

The following :

1. Ping from DMZ-host to LAN-host -> no reply.
2. Ping from LAN-host to DMZ-host -> I get reply's !
3. Ping from DMZ-host to LAN-host -> I no DO get reply's !

It seems that the ARP cache of the firewall needs to get filled with
MAC's from the LAN side to be able to communicate. When the arp
entry's time-out, i have the same problem all over again. I needed to
turn off ProxyARP on the DMZ interface for other DMZ problems.

Anybody can help ?

Thanx
 
Reply With Quote
 
 
 
 
Walter Roberson
Guest
Posts: n/a
 
      12-24-2004
In article <> ,
Thys <> wrote:
:It seems that the ARP cache of the firewall needs to get filled with
:MAC's from the LAN side to be able to communicate. When the arp
:entry's time-out, i have the same problem all over again. I needed to
:turn off ProxyARP on the DMZ interface for other DMZ problems.

:Anybody can help ?

If you turn off proxy arp, then you need to *route* the packets
to the PIX.
--
WW{Backus,Church,Dijkstra,Knuth,Hollerith,Turing,v onNeumann}D ?
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN between Pix firewall behind SpeedTouch ADSL and another PIX DarkoN Cisco 0 10-10-2006 01:15 PM
Is Cisco PIX Application level firewall or Packet level firewall? Learning Cisco Cisco 3 10-15-2005 12:55 AM
PIX Firewall problems Thys Cisco 4 01-03-2005 02:43 AM
Connecting to a PIX firewall using cisco VPM client though a Linksys WAG54G with eth firewall enabled Phil Cisco 1 12-11-2004 12:30 PM
Problems connection to Cisco VPN from behind MS ISA and a PIX firewall Ned Hart Cisco 0 06-06-2004 03:33 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57