Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Can't access the DMZ servers using Public IP

Posted on 2006-07-03
2
Medium Priority
?
375 Views
Last Modified: 2011-09-20
Hi All,

Here is a problem i'm facing, but not sure why this happening. It would be helpful if you can help.

Current config;

Internet --- Router --- PIX
                                   ------ DMZ --- WebServer
                                   ------ Inside --- Workstation

Out Side of the Pix Ip: 209.15.12.30
DMZ Range - 10.11.0.0-254, Ip of the web server 10.11.0.100
Insize Range - 172.16.1.1-254, ip of the workstation 172.16.1.100

PAT is enabled on the inside interface so that the clients can use the internet and DMZ servers
PAT is also enabled on the DMZ  interface on DMZ can reach outside

I have static NAT entry to the webserver
static (dmz1,outside) permit tcp any host 209.15.12.35 10.11.0.100

and have a acess-list to permit web traffice and, this access it listed on the access-group of the ouside interface.

I can access the server from the outside. i can access the server from inside network using the ip address of the DMZ.

But when i try to access the web server from the inside or DMZ network using the ip 209.15.12.35 in the browser it is getting unreachable. Is is creating a problem for my web application which is redirecting differnt part of the application using the url. How can i resolve this ?

Here is the running config of the pix;
PIX Version 6.3(5)
interface ethernet0 auto
interface ethernet1 auto
interface ethernet2 auto
nameif ethernet0 outside security0
nameif ethernet1 inside security100
nameif ethernet2 dmz1 security10
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
names
access-list aclout1 permit tcp any host 209.15.12.35 eq www
pager lines 24
icmp permit any outside
icmp permit host 0.0.0.0 outside
icmp permit any inside
icmp permit host 0.0.0.0 inside
icmp permit any dmz1
icmp permit host 0.0.0.0 dmz1
mtu outside 1500
mtu inside 1500
mtu dmz1 1500
ip address outside 209.15.12.30 255.255.255.0
ip address inside 172.16.1.1 255.255.255.0
ip address dmz1 10.11.0.1 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
pdm location 172.16.1.100 255.255.255.255 inside
pdm location 172.16.1.0 255.255.255.0 inside
pdm history enable
arp timeout 14400
global (outside) 10 interface
global (dmz1) 10 interface
nat (inside) 10 172.16.1.0 255.255.255.0 0 0
nat (dmz1) 10 10.11.0.0 255.255.255.0 0 0
static (dmz1,outside) 209.15.12.35 10.11.0.100 netmask 255.255.255.255 0 0
access-group aclout1 in interface outside
route outside 0.0.0.0 0.0.0.0 209.15.12.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout sip-disconnect 0:02:00 sip-invite 0:03:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
http server enable
http 172.16.1.100 255.255.255.255 inside
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
telnet timeout 5
ssh timeout 5
console timeout 0
terminal width 80
--------------------------End Pix Config

Thanks.


 
0
Comment
Question by:tssiva
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 13

Expert Comment

by:prashsax
ID: 17033120
static (dmz1,outside) 209.15.12.35 10.11.0.100 netmask 255.255.255.255 0 0
access-list aclout1 permit tcp any host 209.15.12.35 eq smtp
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 1500 total points
ID: 17033764
>I can access the server from the outside. i can access the server from inside network using the ip address of the DMZ.
This indicates that your configuration for statics and access-lists are correct

>But when i try to access the web server from the inside or DMZ network using the ip 209.15.12.35 in the browser it is getting unreachable.
That is correct. This is pure design principles of the PIX and order of packet flow and nat

>How can i resolve this ?
You can't. You can never access natted public IP's from the inside directly.

HOWEVER, there is some saving grace in that you are trying to go from inside to DMZ and the natted host is on the DMZ. Depending on the OS version of your PIX, you may be able to use ALIAS command to perform dnat:
 alias(inside) 209.15.12.35 10.11.0.100 255.255.255.255

Understanding the alias Command for the Cisco Secure PIX Firewall
http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_tech_note09186a0080094aee.shtml
 
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …
Suggested Courses

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question