[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details

Nat and transparent firewall issue - cisco ASA

Asked by heathcote123 in Cisco PIX Firewall, Enterprise Firewalls, Networking Hardware Firewalls

Tags: cisco, asa, 5500

Big thanks to anyone that can help with this:

I have the following situations:

A load-balancing router performing NAT from a public interface to a private one (172.27.0.0). It has a translation from x.x.x.x to 172.27.0.12.

Behind this is a server and a few PC's. A A cisco asa doing transparent firewalling is also present between the switch and one server (172.27.0.12)

The server is on the same subnet and is seperated from the LAn with the cisco.

The aim is to be able to access the web server publically and from the lan.

Currently I have an 'allow ip any any' on both interfaces.

I can access the web server from 172.27.0.x without problems, but when I try to access it externally, it does not connect.

A 'show conn' sees the attempted connection with a flag of SaAB - suggesting a problem with the syn/ack bit.

Any clues?
 
Loading Advertisement...
 
[+][-]03/19/08 10:25 AM, ID: 21163653Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03/19/08 01:08 PM, ID: 21165369Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03/20/08 05:32 AM, ID: 21170535Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08/31/09 01:00 PM, ID: 25225895Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091021-EE-VQP-81 / EE_QW_2_20070628