Solved

Packets not being returned to server inside a PIX 506E

Posted on 2006-11-27
4
233 Views
Last Modified: 2013-12-07
I have a server on a network inside a PIX 506E. I have an external device that I can ping from the PIX, and the external device responds, which can be seen on the PIX command line interface. I have a server inside the PIX which is attached to the PIX via a switch. The server can send a ping request out to the external device, which responds (as seen on the PIX command line by use of debug packet), however the response never gets sent back through to the internal server.

I am also having problems getting Internet Explorer on that internal server to open up websites by domain name (such as windowsupdate.microsoft.com). Some websites it will open, others it won't. nslookup can resolve a name for windowsupdate.microsoft.com, but IE seemingly can't. IE can open websites by IP address (like http://123.456.789.123/index.htm).

Does anyone have any idea what the problem might be, and how I can resolve it?
0
Comment
Question by:AGBrown
  • 2
  • 2
4 Comments
 
LVL 4

Accepted Solution

by:
pakitloss earned 500 total points
ID: 18022676
As for icmp try:

access-list inbound permit tcp any any eq echo
access-list inbound permit icmp any any echo-reply
access-list inbound permit icmp any any traceroute

If the server is a domain controller try configuring forwarders to point to your external DNS.
0
 
LVL 12

Author Comment

by:AGBrown
ID: 18022730
The server is a standalone server, the NIC is setup the same way as another private network in the same colocation facility, and the other private network seems to work fine. Given that nslookup works for domain name resolution, this might be a problem with IE instead.

The icmp commands worked. Can you explain why I need to explicitly state inbound access commands for icmp if I'm only expecting a reply to icmp requests that originated inside the network?

It is useful to know that the problems are not related.
0
 
LVL 4

Expert Comment

by:pakitloss
ID: 18024448
Because there is no translation rule for ICMP by default on a PIX. Ok.... so now DNS.... if you think it may be IE then try downloading Firefox and installing it and see if it works.
0
 
LVL 12

Author Comment

by:AGBrown
ID: 18029776
I just read up on the icmp as it was ringing bells but couldn't remember it properly. It would seem that its not that there's no translation rule, per se, but that although outbound icmp is permitted, the incoming reply is denied by default.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml

W.r.t. the problems with IE, it would seem that I've been having DNS problems. I'm using another DNS server for the moment.

Thanks for the help

Andy
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now