Firewall Wizards mailing list archives

RE:RE:Internal Users hitting the external NAT address


From: "Payne, Patrick" <Patrick.Payne () Select com>
Date: Fri, 15 Jun 2001 14:10:36 -0400

It looks to me like you have the commands corrrect so I'm not sure where
you're going wrong.  Cisco recommends rebooting the PC to clear cached DNS
entries.  If that doesn't work, two good links for the use of this command
are:
http://www.cisco.com/warp/customer/110/alias.html
http://www.cisco.com/warp/customer/110/pixfaq.shtml#Q15
I can tell you I have seen this work so don't give up just yet.

Good luck,
Pat Payne

Message: 1
From: yehuda <yehuda () essutton com>
To: "'firewall-wizards () nfr com'" <firewall-wizards () nfr com>
Date: Wed, 6 Jun 2001 11:44:41 -0400
charset="iso-8859-1"
Subject: [fw-wiz] RE: Internal users hitting the external NAT address

I thought I understood, but when I try it, it doesn't change anything. this
is what I got...
(192.168.xxx.zzz is a linux machine on the same interface of the pix as the
server)

PIX(config)# alias (dmzinterface) 192.168.xxx.xxx 6y.yyy.yyy.yyy
255.255.255.255
PIX(config)# show alias
alias (dmzinterface) 192.168.xxx.xxx 6y.yyy.yyy.yyy 255.255.255.255
PIX(config)# show xlate global 6y.yyy.yyy.yyy
Global 6y.yyy.yyy.yyy Local 192.168.xxx.xxx static nconns 0 econns 1
PIX(config)# clear xlate local 192.168.xxx.xxx
PIX(config)# clear xlate local 192.168.xxx.zzz
PIX(config)#

[root@linuxbox root]# ping server.example.com
PING server.example.com (6y.yyy.yyy.yyy): 56 data bytes

--- server.example.com ping statistics ---
3 packets transmitted, 0 packets received, 100% packet loss
[root@linuxbox root]#
[root@linuxbox root]# ping server.example.com
PING server.example.com (6y.yyy.yyy.yyy): 56 data bytes

--- server.example.com ping statistics ---
3 packets transmitted, 0 packets received, 100% packet loss
[root@linuxbox root]# telnet server.example.com 25
Trying 6y.yyy.yyy.yyy...

_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards


Current thread: