get PIX translate Source AND Destination addresses

Discussion in 'Cisco' started by ct.beuger, Aug 6, 2004.

  1. ct.beuger

    ct.beuger Guest

    We have two ISP’s, two PIXes, two web servers and one big problem.

    In the sketch I’ve drawn the network.
    Both servers run Citrix and IIS that needs to be accessible from outside.
    PIXa is for both servers the default gateway.
    The PIX and the Linux box do address translation. The PIX rewrites
    the destination addresses, the Linux the destination and the source
    address.

    When ISPa is unavailable we update only the DNS entries for our servers
    and people connect to us over ISPb.

    The Linux box will be replaced by a PIX.
    Is there a way to full NAT a connection so that the requests to
    the server seem to be coming from PIXb instead of the actual client?

    Tanks in advance,

    Chris

    +--------------------------------------------------------+
    | Internet / |
    |. ,'-. |
    | '---. _.--' `. |
    | `-----+------'' ,`-.----------. |
    | ,--------+--. ( ISPb ) |
    | ( ISPa ) `------------+' |
    | `-------+---' __,,....------------.....__| |
    | |,.--'' LAN |`'--..__ |
    | _.-''| | `-.|
    | ,-' ++-----+ +-+-----+ |
    |,' | PIXa ........|..............|... linux | |
    | +------+ | | +-------+ |
    | | | |
    | | | |
    | +----------+-+ ++-----------+ |
    | | ServerA | | ServerB | |
    |`._ | | | | |
    | `._ +------------+ +------------+ |
    | `-.._ _,.-'|
    | `'--...__ ___..--'' |
    | `''''------------''''' |
    +--------------------------------------------------------+

    (An other approach to redundant internet connection is welcome BTW)
     
    ct.beuger, Aug 6, 2004
    #1
    1. Advertisements

  2. ct.beuger

    Hansang Bae Guest

    [snip]

    Sorry, I can't help you with the pix. But quick question..you'r using
    PAN so I'm assuming you're on Linux. What did you use to draw the ascii
    art above?


    --

    hsb

    "Somehow I imagined this experience would be more rewarding" Calvin
    *************** USE ROT13 TO SEE MY EMAIL ADDRESS ****************
    ********************************************************************
    Due to the volume of email that I receive, I may not not be able to
    reply to emails sent to my account. Please post a followup instead.
    ********************************************************************
     
    Hansang Bae, Aug 7, 2004
    #2
    1. Advertisements

  3. Richard Sanderson, Aug 7, 2004
    #3
  4. ct.beuger

    ct.beuger Guest

    The ASCII art is made with jave (jave.de). It’s in java so cross platform.
    Actually I run PAN under Windows.
     
    ct.beuger, Aug 9, 2004
    #4
  5. ct.beuger

    Hansang Bae Guest

    Thanks. I actually looked around and found "Email Effects" Pretty
    decent. ASCEditor4 isn't too bad either once you get used to its
    quirks. Didn't know pan run under windows. I'm always looking for a
    good newsreader (Gravity's pretty decent)....Thanks for the update
    though.


    --

    hsb

    "Somehow I imagined this experience would be more rewarding" Calvin
    *************** USE ROT13 TO SEE MY EMAIL ADDRESS ****************
    ********************************************************************
    Due to the volume of email that I receive, I may not not be able to
    reply to emails sent to my account. Please post a followup instead.
    ********************************************************************
     
    Hansang Bae, Aug 10, 2004
    #5
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.