Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

PIX 506e static nat for services

Posted on 2004-10-26
2
Medium Priority
?
179 Views
Last Modified: 2010-04-09
I have a linux box in my dmz that I am trying to allow access to the web server in my private network.  I added the following to my PIX to allow a static nat

My pix outside interface is 172.16.0.9, inside 10.0.0.2

static (inside,outside) 172.16.0.10 10.0.0.10 netmask 255.255.255.255 0 0
access-list outside_access_in permit tcp any host 172.16.0.10 eq www

The linux box IP is 172.16.0.14 on the same network as the pix outside interface.  But when I try and connect using the 172.16.0.10 address I receive a 'no route to host' error.

The route table of the linux box is
172.16.0.0    *                   255.255.254.0   U    0 0 0   eth0
loopback      gentoo          255.0.0.0            UG 0 0 0   lo
default         172.16.0.2    0.0.0.0                UG 0 0 0   eth0

So why am I getting this error?

0
Comment
Question by:bdebelius
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 2000 total points
ID: 12415411
The host is local to you, so where are you seeing this error, on the gentoo box, or the PIX?
Do you have proxyarp enabled for the outside interface?
What is the subnet mask on the outside interface of the PIX?
What is the default gateway of the box 10.0.0.10 ?
0
 

Author Comment

by:bdebelius
ID: 12422461
I had proxyarp disabled.  Thanks.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question