[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

No Route to Outside from DMZ

Posted on 2008-11-05
2
Medium Priority
?
326 Views
Last Modified: 2008-11-12
Hiya People...

Right, I have a Load Balancer which I need to NAT Straight through to the DMZ which sits on a PIX 515e.

even when I allow NAT Straight through to the DMZ the packets get there but it looks like they don't get back.

I get a NO Route to OutsideIP from DMZ Server IP (192.168.30.4)

the network is as follows...
External Routers - 123.123.123.1 and 123.123.123.3
External Load Balancer - ExternalIPs eg 123.123.123.2 and 123.123.123.4
PIX Outside IP - 123.123.123.5
PIX dmz int IP - 192.168.30.6
DMZ webserver - 192.168.30.4

The machine in the DMZ can access webpages and has good internet access.

The pix has a static route which i 0.0.0.0 0.0.0.0 123.123.123.3 - straight out of the External Router...

anybody have any hints please?

Thanks
0
Comment
Question by:chesterzoo
2 Comments
 
LVL 32

Accepted Solution

by:
rsivanandan earned 1500 total points
ID: 22904340
Do you have all the nat statements with supplementing acl's in place? It should look something like this;

static (inside,outside) 123.123.123.2 192.168.30.x netmask 255.255.255.255

access-list <something> permit tcp any host 123.123.123.2 eq http

access-group in interface outside

Post the config if you have any further questions.


Cheers,
Rajesh
0
 
LVL 2

Author Comment

by:chesterzoo
ID: 22905793
yes ive got all the ACL's in place...

ill grab the config in a bit...

Cheers
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

873 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question