Re: Pix static problem

From: scook@forsythemca.com
Date: Tue Feb 11 2003 - 15:39:16 GMT-3


I'm assuming that you are talking about internal users hitting the web
server with its DNS name. If you are, you can either change your internal
DNS to the private IP address of your web server or use the alias command:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/cmdref/ab.htm#1083304

The weakness of the alias command is that I still don't think it's
supported by PDM. That may have changed recently.

Good luck.

                                                                                                                                 
                      "george gittins"
                      <g.gittins@edinbur To: <ccielab@groupstudy.com>
                      g.esc1.net> cc:
                      Sent by: Subject: Pix static problem
                      nobody@groupstudy.
                      com
                                                                                                                                 
                                                                                                                                 
                      02/11/2003 12:29
                      PM
                      Please respond to
                      "george gittins"
                                                                                                                                 
                                                                                                                                 

I have a problem with my pix , I have two dns servers with internal ip that
I set up static mappings. However the webserver on the dmz zone I can only
hit it via ip, so im assuming that the internal dns mappings is not working
when I do a show conduit statement I show no hits for my internal dns.

The ip of my internal dns servers are

10.16.1.249 & 250

and on the outside

204.158.241.249

204.158.241.250

I place these statements

Static (inside, outside) 204.158.241.250 10.16.1.249 netmask
255.255.255.255

Same for the other.

And a conduit statement

Conduit permit 204.158.241.249 eq 53 any

And no luck

Any suggestions

George Gittins

Network and Computer Maintenance Supervisor
.
--------------------------------------------------------------------------------------------------------------------
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom
they are addressed.
If you have received this email in error please notify the
originator of the message. This footer also confirms that this
email message has been scanned for the presence of computer viruses.
.



This archive was generated by hypermail 2.1.4 : Sat Mar 01 2003 - 11:06:18 GMT-3