Solved

Web server hosting the port 80 redirection cannot access itself

Posted on 2007-12-05
2
316 Views
Last Modified: 2010-04-09
Port 80 on the external address of our Pix 501 (68.179.x.y) is redirected to our internal Web Server at  ip address 10.200.6.25. Everyone can access the web site properly, internal as well as external clients. Except from the Web server itself. If I go to address 68.179.x.y in IE from the web server itself, I get Page Cannot be displayed.

Is this a normal Cisco Pix behaviour preventing a redirected host to access itself from the external interface, or is it a misconfiguration on our part ?
0
Comment
Question by:ndidomenico
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 19

Accepted Solution

by:
nodisco earned 500 total points
ID: 20415078
No its quite normal.  The PIX won't let traffic go back in the interface it originates from - the originating traffic is going out the PIX outside ip as thats where the address is but needs to come back in as its port-forwarded internally.

won't work.

If you want a quick workaround - put a DNS A record for the URL name - e.g. www.mycompany.com to the 10.200.6.25 address on your DNS server - or even just create an entry for this in the hosts file
0
 

Author Comment

by:ndidomenico
ID: 20419264
What is the security or technical reason for the Pix to block this form of out/in traffic ? This Pix is replacing a low-end Linksys router which was not blocking this sort of traffic.

For the workaround, I'm afraid it won't work in this case. Displaying the web page we need is done by first going to another web page on the Internet, which has a link that brings us to our web page, except that the link on that site is using an IP address (the external ip of the Pix) instead of a url name. Can we get arout this without having to modify this external web page ?
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question