Solved

pix 515 with internal outside and dmz cannot reach internet from dmz

Posted on 2003-11-04
2
400 Views
Last Modified: 2010-04-17
what statments are required for my dmz to access the outside interface? I can currently access the dmz from the inside and my internet site on my dmz works externally I just cannot reach the internet from the webserver.
0
Comment
Question by:CMorehosue
2 Comments
 
LVL 13

Accepted Solution

by:
td_miles earned 250 total points
Comment Utility
I'm assuming you current config looks something like this (parts of):

global (outside) 1 interface
nat (inside) 1 192.168.1.0 255.255.255.0 0 0
static (dmz,outside) tcp w.x.y.z 80 172.16.1.11 80 netmask 255.255.255.255 0 0

(where w.x.y.z is the real IP address that you access your webserver by).

To add Internet access to the DMZ, add the following line:

nat (dmz) 1 172.16.1.0 255.255.255.0 0 0

which will allow the traffic from the "dmz" interface with ip address in the subnet 172.16.1.0 to be NAT'ed to the global outside IP address. The dmz interface will be a higher level than the outside, so it should just work with this. (obviously change the interface name to whatever yours is called and the IP address range to your DMZ range)

For reference:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/config/bafwcfg.htm#1067203
0
 

Author Comment

by:CMorehosue
Comment Utility
Thanks TD that was my problem worked like a charm
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

It happens many times that access list (ACL) have to be applied to outgoing router interface in order to limit some traffic.This article is about how to test ACL from the router which is not very intuitive for everyone. Below scenario shows simple s…
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now