Solved

Configure pix 501 to access outside ip from inside

Posted on 2009-07-06
4
305 Views
Last Modified: 2012-05-07
Ok, so we have a pix 501 firewall.  Inside we have 2 different web servers using 2 outside ip addresses.  I haven't been able to connect to either outside IP form any computer inside the network.  I was able to configure NAT to allow access, but it breaks all other internet access.  If anyone has any insight on how to configure this I would greatly appreciate it.
0
Comment
Question by:bhmahler
4 Comments
 
LVL 15

Expert Comment

by:Robert Sutton Jr
ID: 24787018
Could you post a copy of your complete config here please. You can remove/change your Public Ip information for your network before posting it here for your own protection. Thanks in advance.
0
 
LVL 20

Accepted Solution

by:
RPPreacher earned 500 total points
ID: 24787033
This is a pretty common issue

www.example.com is your outside name

When users resolve www.example.com, it resolves to aaa.bbb.ccc.ddd (public address)

The PIX does not allow traffic to hairpin (go out and in on same interface).

Easy solution.  Add DNS zone example.com to your internal DNS server.  Add A record www.example.com to resolve to INTERNAL IP.
0
 
LVL 28

Expert Comment

by:Jan Springer
ID: 24787581
0
 
LVL 8

Author Closing Comment

by:bhmahler
ID: 31600247
I went ahead and configured it this way.  Thanks
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
Along with being a a promotional video for my three-day Annielytics Dashboard Seminor, this Micro Tutorial is an intro to Google Analytics API data.
Many functions in Excel can make decisions. The most simple of these is the IF function: it returns a value depending on whether a condition you describe is true or false. Once you get the hang of using the IF function, you will find it easier to us…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now