I am having trouble with xlate timeouts on a pix firewall. I have a static translation from our DMZ network to our INTERNAL network. I have added and access list which currently allows all icmp and ip traffic in the DMZ interface. After clearing the xlate, an initial ping from a DMZ host to an INTERNAL host returns a "request timed out". However, a ping from an internal host to the DMZ host works and after this successful ping the DMZ server is now able to ping the internal host...Until the xlate times out that is. I thought that the static statement would setup the xlate with traffic going in or out as long as the access-list allows it. Is this incorrect?
If needed, I can post the pix config. However, I would need to trim it down quite a bit because of other interfaces and entries that muddy the water. Thanks in advance,
Danny
Start Free Trial