Solved

PIX DMZ Internet access

Posted on 2008-06-10
7
859 Views
Last Modified: 2013-11-16
I have a Cisco PIX 515 with a dmz interface enabled. The pc I have put in the dmz can get to the internal network through an access list, but is unable to get to the internet. Below is my DMZ config.

access-list dmz extended permit ip any any

static (dmz,inside) 10.3.0.0 10.3.0.0 netmask 255.255.255.0
static (inside,dmz) 10.0.0.0 10.0.0.0 netmask 255.0.0.0
static (dmz,outside) 207.136.182.4 10.3.0.4 netmask 255.255.255.255 dns
static (dmz,outside) 207.136.182.3 10.3.0.3 netmask 255.255.255.255 dns
static (dmz,outside) 207.136.182.30 10.3.0.5 netmask 255.255.255.255
static (dmz,outside) 207.136.182.7 10.3.0.6 netmask 255.255.255.255
static (dmz,outside) 207.136.182.8 10.3.0.7 netmask 255.255.255.255
access-group outside in interface outside
access-group dmz in interface dmz
0
Comment
Question by:dtadmin
7 Comments
 
LVL 28

Expert Comment

by:batry_boy
ID: 21754770
What do your "nat" and "global" statements look like?
0
 

Author Comment

by:dtadmin
ID: 21754845
global (outside) 1 interface
nat (inside) 0 access-list nonat-vpn
nat (inside) 1 0.0.0.0 0.0.0.0
0
 
LVL 15

Expert Comment

by:Voltz-dk
ID: 21755943
nat (dmz) 1 0 0
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:dtadmin
ID: 21755975
what exactlly is nat (dmz) 1 0 0 telling me?
0
 
LVL 15

Expert Comment

by:Voltz-dk
ID: 21755987
It says that all access from DMZ when going "outbound" (less secure interface), should be NATed to the global pool on that interface with id 1.

In this case any traffic from DMZ that goes to Internet will be PATed into the PIX outside IP. (Same as is done for traffic from inside).
0
 
LVL 15

Expert Comment

by:Voltz-dk
ID: 21755991
Well, since you have statics it's not really true that it's ANY traffic.  Cuz the statics have precedense, and thus those will not use the dynamic NAT.
0
 
LVL 6

Accepted Solution

by:
raptorjb007 earned 500 total points
ID: 21756244
Voltz-dl is correct.

Try adding

nat (dmz) 1 0.0.0.0 0.0.0.0

This command will configure your Pix to apply PAT or "NAT overload" to the DMZ VLAN, it is the counterpart to the "nat (inside) 1 0.0.0.0 0.0.0.0" command you already have configured for the inside vlan. Without a the nat command applied to the dmz vlan any device without a static translation will be unable to access the internet as it cannot be translated to an internet address.

Basically, with the "nat(dmz) 1 0 0" command applied, any device on your DMZ VLAN without a static translation will utilize the outside interface's IP address to access the internet.
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question