Solved

PIX 506e static nat for services

Posted on 2004-10-26
173 Views
Last Modified: 2010-04-09
I have a linux box in my dmz that I am trying to allow access to the web server in my private network.  I added the following to my PIX to allow a static nat

My pix outside interface is 172.16.0.9, inside 10.0.0.2

static (inside,outside) 172.16.0.10 10.0.0.10 netmask 255.255.255.255 0 0
access-list outside_access_in permit tcp any host 172.16.0.10 eq www

The linux box IP is 172.16.0.14 on the same network as the pix outside interface.  But when I try and connect using the 172.16.0.10 address I receive a 'no route to host' error.

The route table of the linux box is
172.16.0.0    *                   255.255.254.0   U    0 0 0   eth0
loopback      gentoo          255.0.0.0            UG 0 0 0   lo
default         172.16.0.2    0.0.0.0                UG 0 0 0   eth0

So why am I getting this error?

0
Question by:bdebelius
    2 Comments
     
    LVL 79

    Accepted Solution

    by:
    The host is local to you, so where are you seeing this error, on the gentoo box, or the PIX?
    Do you have proxyarp enabled for the outside interface?
    What is the subnet mask on the outside interface of the PIX?
    What is the default gateway of the box 10.0.0.10 ?
    0
     

    Author Comment

    by:bdebelius
    I had proxyarp disabled.  Thanks.
    0

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    IT Security CISA, CISSP & CISM Certification

    Master the advanced techniques required to protect network resources from external threats with the IT Cyber Security bundle. Built around industry best-practice guidelines, the IT Cyber Security bundle consists of three in-depth courses.

    Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
    Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
    Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

    884 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    24 Experts available now in Live!

    Get 1:1 Help Now