static (inside,lab) 10.10.150.0 netmask 255.255.255.0
seemed to do the trick I can get from inside to lab now.
Still no ICMP even though I have
icmp permit any lab
icmp permit any inside
It also wouldn't work adding a global using the public IP... normally a telnet test to the port shuts down right away indicating there is a firewall, with the global in place it times out instead, I suspect for some reason the device on the lab network is having problems replying to the NAT'd global IP. Maybe a proxy arp problem on the interface, I don't know it's almost 2am lol... I think the static is what we want but I would like to know why the global doesn't work anyways, along with icmp...
I assume I need static mappings and acl's to get from lab to inside as normal.
1 last quick edit, with the global in place and no static, my pings and telnet tests get no log on the pix. With the static, telnet tests work, but icmp generates a log stating unable to portmap from the lab to the inside (the reply packet)... shouldn't think be open by way of SPI / xlate table?
|