Hosts of inside do NOT speak to each other - Pix 506, Pix 515E
Good Morinig, everyone,
We have Pix515E and Pix506E, both are configured to pretty much the same: IP private networks inside, entering NAT for web/SSH servers for access. The problem is: inside hosts can not access these servers with NAT translation (cannot ping, cannot http, can't ssh). I thought that they are all the same network and will not affect the pix firewall, but why they don't communicate with each other? We used to use CheckPoint and never have such a problem for private network access intra-problem:
(a compendium see the running-config below): >
Result of the firewall command: 'show running-config '.
: Saved
:
6.3 (3) version PIX
interface ethernet0 car
Auto interface ethernet1
ethernet0 nameif outside security0
nameif ethernet1 inside the security100
names of
name 192.168.1.100 PrvEcommerce
name import 192.168.1.150
name 206.246.202.19 import-outside
name 209.96.203.2 gateway-cnf
the name 209.96.203.21 shark
name 206.246.202.22 SU-PC
name 192.168.1.50 su-pc
outside_access_in list access permit tcp any host 206.246.202.20 eq www
outside_access_in access-list deny shark host tcp everything
outside_access_in list access permit tcp any host 206.246.202.20 eq 3306
outside_access_in list of access permitted tcp 209.96.203.0 255.255.255.192 host 206.246.202.20 eq ssh
outside_access_in list of access allowed icmp all 206.246.202.0 255.255.255.0 echo
outside_access_in list access permit tcp any host 206.246.202.21 eq www
outside_access_in list of access permitted tcp 209.96.203.0 255.255.255.192 host 206.246.202.21 eq ssh
outside_access_in list access permit tcp any host 206.246.202.20 eq https
outside_access_in list access permit tcp any host import out eq www
outside_access_in list access permit tcp any host import out eq 819
outside_access_in list access permit tcp any host import out eq 3306
outside_access_in tcp access list refuse a whole
pager lines 24
ICMP allow any response of echo outdoors
Outside 1500 MTU
Within 1500 MTU
IP outdoor 206.246.202.18 255.255.255.248
IP address inside 192.168.1.1 255.255.255.0
alarm action IP verification of information
alarm action attack IP audit
location of PDM PrvEcommerce 255.255.255.255 inside
location of PDM 206.246.202.20 255.255.255.255 outside
location of PDM 192.168.1.200 255.255.255.255 inside
location of PDM 192.168.1.2 255.255.255.255 inside
location of PDM 206.246.202.21 255.255.255.255 outside
location of PDM 206.246.194.0 255.255.255.0 outside
location of PDM 209.96.203.0 255.255.255.0 outside
location of PDM 209.96.203.0 255.255.255.192 outside
location of PDM import 255.255.255.255 inside
location of PDM import-outside 255.255.255.255 outside
PDM bridge-cnf 255.255.255.255 out place
location of PDM 255.255.255.255 out shark
PDM location su-pc 255.255.255.255 inside
PDM 255.255.255.255 out SU-PC slot
location of PDM 10.1.1.0 255.255.255.0 inside
PDM logging 100 information
history of PDM activate
ARP timeout 14400
Global (outside) 2 206.246.202.57 - 206.246.202.62 netmask 255.255.255.248
Global 1 interface (outside)
Global (inside) 8 su-pc - 192.168.1.200
Global (inside) 4 192.168.1.10 - 192.168.1.240 netmask 255.255.255.0
NAT (inside) 1 192.168.1.0 255.255.255.0 0 0
public static 206.246.202.20 (Interior, exterior) PrvEcommerce netmask 255.255.255.255 0 0
static (exterior, Interior) PrvEcommerce 206.246.202.20 netmask 255.255.255.255 0 0
public static 206.246.202.21 (Interior, exterior) 192.168.1.200 netmask 255.255.255.255 0 0
public static 192.168.1.200 (exterior, Interior) 206.246.202.21 netmask 255.255.255.255 0 0
public static import import-outside (Interior, exterior) mask subnet 255.255.255.255 0 0
public static import (exterior, Interior) import-outside netmask 255.255.255.255 0 0
static (inside, outside) pc-su - SU-PC netmask 255.255.255.255 0 0
Access-group outside_access_in in interface outside
Route outside 0.0.0.0 0.0.0.0 206.246.202.17 1
Timeout xlate 0:05:00
Timeout conn 01:00 half-closed 0:10:00
: end
All suggestions and ideas are greatly appreciated.
Sean Chang
What IPs try internal users access? 192.168.1.x or 206.246.202.x?
I don't fully understand your situation, but your NAT Setup is very weird. I've never used "global (inside)..."
If users try to get to 192.168.1.x, try to remove these lines:
static (exterior, Interior)...
Global (outside) 2...
Global (inside) 8...
Global (inside) 4...
Tags: Cisco Security
Similar Questions
-
How can I configure icloud on my iPhone and a windows PC?
Have you followed these steps?
-
Can I allow an application for one person on my family share but does not allow for each other?
You can't delegate who has access and who doesn't have access to the applications. You can lock devices with age restrictions, so only items appropriate age are at their disposal. Or you can hide your list purchases. The purchased app can then be displayed when you want to share with someone else, then be hidden again once the application is downloaded on their device.
I hope this helps.
SI10
-
HA when ESX host are not equal to each other
Hello
Please, describe me my misunderstanding of HA...
I have 3 servers ESX and 2 of them have 4 CPU 1 only have 2 CPU. I can create cluster HA with these 3 hosts, and if I can - how VM is migrated to ESX with 2 CPU, when one or two ESX with 4 CPUS will fail, in case when I have VMS with 4 CPUS per VM (even though admission control will be disable)?
A vm with v 4cpus will not be able to be propelled to a host with only 2 physical processors. HA will not be able to failover in this case, even if the HA admission control is disabled.
-
My laptop computer and printer do not communicate with each other.
I went to "printers and devices in the control panel and my laptop has an icon of troubleshooting beside him. I tried to search for updates/drivers solve the problem and nothing works. It says ' unknown device is not a driver. My fax, copier and scanner work, but the printer does not work because there is a problem with my laptop. I could not use my printer because I was out of ink for 2 months, then I buy ink and now I can't print! Ink for a Lexmark is not cheap.
I hope someone can help!
Karen
Because my printer is a Lexmark, I had to go to the Lexmark he site and search "Drivers" under which specific printer, you have it downloaded on my computer and loaded this way to connect my laptop with my printer.
-
VLAN SRP527W do not talk to each other
Hello everyone,
I'll keep it simple for the sake of the discussion.
I have a SRP527W router that is connected to a switch L2 (a TP-Link... I know, it's not a Cisco...). and a PC and a printer connected to the switch. Now, I want to have the PC and the printer on 2 VLANS.
I created 2 VLANS on the PSR (192.168.1.0/24 and 192.168.2.0/24) and I assigned the Lan 1 port at a time. The RPS is a DHCP server so I have SRP 192.168.1.1 and 192.168.2.1 installation provides IP addresses to the 2 VLAN.
I have Setup VLAN 1 and 2 switch, 2 port assignment in the VLAN 1 and VLAN 2 3 port (port 1 is the trunk and connects to the SRP).
When I start the PC and the printer they get their correct addresses from VLAN respective (PC: 192.168.1.30 and printer: 192.168.2.30) but for the sake of Odin, I can't see the printer from the PC. ESP was Inter VLAN routing active. Moreover, the switch has address 192.168.1.2
What I am doing wrong?
Thanks for the ideas, you can provide.
-Mike * start things in the Office *.
No problem at all, don't send me an email. We can get something set up maybe tomorrow.
-Tom
Please mark replied messages useful -
Windows Vista &; Palm Centro 690 do not talk to each other
After my other phone went through the washing machine I changed to this Palm unit. Active, came home and installed the synchronization software, worked well. A few days later tried to synchronize again, no luck. I'm working on for a few weeks trying to get it working again! I talked to the local office of Verizon, they suggested that I talk to a technical support. Them, spent more than an hour on the phone with them the uninstallation of the software, called again, download the new software, once again, still nothing, done a reset and a format and still nothing. Have been using the Palm as a normal phone and that's fine. I was unable to figure out what to do. I even talked to Hp technical support, is not their problem! talk to the people of palm. So here, I looked through your forms but did not find everything that is related to the Centro and Vista. I'm almost ready to try anything that seems reasonable.
Thank you, who finally did the trick, don't know what the difference is / was, but I don't like as it works again. Next time I try a synchronization, I'll try the front USB port and see what happens. Gluton for the trouble I guess!
Once again, thanks a lot for your help. He is LARGELY APPRECIATED.
kenz5103
Message relates to: Centro (Verizon)
-
Microsoft 3000 wireless keyboards; they will interact with each other
I have 2 PC and I would like to replace the wired keyboards for 2 sets of Microsoft 3000 keyboard, will they interact with each other and can I change Ch / Freq of the units
Hi Baz,
Each keyboard has different frequency and will not interact with each other.
-
Two Xbox 360 Wireless controllers Microsoft will interfere with each other?
* Original title: Microsoft Xbox 360 for Windows wireless controllers... Two will interfere with each other?
Controller: Microsoft Xbox 360 Wireless Controller for Windows (JR9-00011)
Operating systems: Windows 7
I have two PCs located in the same room. Is it possible to set up a wireless for each of them so that they do not interfere with each other?
Hello
I would like the links and see if it helps.
How to set up your Xbox 360 to your Windows PC controller
Set up your Xbox 360 for Windows gamepad
If you have other questions, please post your request in the Xbox forums for assistance on this issue.
Hope this information helps.
-
2. separate menu which are unrelated to each other
need to have 2 separate menu that are not related to each other
Hello
You can try the Menu manual. In this game you decide the sequence of each Menu item
To activate the Menu manual
- Create a menu in design mode
- Click on Options (the blue circle top-right)
- Select the type of Menu as manual
- Then select the Menu item and click on '+' sign to add several menu items and customize according to your need
If you're talking about something else then give use more details on what you're trying to do.
Concerning
Vivek
-
Hello. Under the network of my machine Windows 8 folder, I can see all the devices on the network. This includes a printer, my computer Windows 7 (what I can access), an Apple TV (from special software), a wireless hard drive, the router and a digital recorder.
The Windows 7 machine, I can only see the router and the printer. On special software, the Apple TV does not either. When you perform the Windows 8 computer host as a server for the special software, the Windows 7 machine could not see it on the special software. This means that there is something wrong on the Windows 7 this machine is not allowing him to detect other devices.
In a game of LAN, Windows 7 and Windows 8 computers can't see each other.
All devices are on the internet and I am posting this from the Windows 7 machine right now.
Windows 7 and Windows 8 machine are on the same network.
No device is on a host group and the group home service is disabled.
Peer networking is enabled.
Network discovery is turned on.
Both connections are set to private/Home.
Originally, the Windows 7 machine has been on his own home group and could be seen by anything. After a few hours, I finally got out of the home group, how other devices could see him then. However, he cannot always see other devices.
How can I get the Windows 7 machine to see other devices? I am at a loss. Is there a service that I have disabled right now that needs to be enabled? I don't know what to do.
Hello
Please contact Microsoft Community.
Disable the security software and check.
http://Windows.Microsoft.com/en-in/Windows7/disable-antivirus-software
Warning: Antivirus software can help protect your computer against viruses and other security threats. In most cases, you should not disable your antivirus software. If you do not disable temporarily to install other software, you must reactivate as soon as you are finished. If you are connected to the Internet or a network during the time that your antivirus software is disabled, your computer is vulnerable to attacks.
Also check out the link below and check if that helps.
Why can I not see other computers on my network?
http://Windows.Microsoft.com/is-is/Windows7/why-can-t-I-see-other-computers-on-my-network
If the problem persists, or you have questions about Windows, let know us, we will be happy to help you.
-
My HP laptop has installed Win7 Ult, the Fujitus Win7 Pro.
Both computers were sharing the files back, outside a residential group, for a period of time. One day, they are stopped. No changes have been made to computers. I tried a restore of the system on each of them, and it did not help. I re windows loaded on the HP and that did not help. I don't think that it is only a permission of the questions that I used a windows machine 7 third to map actions to each of the individual laptops using their respective IDs. I can transfer files from one of them the "machine in the middle", then the action of the other, or as a copy/paste between them directly.
WSD and NetBT will not solve one machine for others, but all other computers on the network will dispay on each machine. Only, they refuse to see each other. I have disabled the firewall. Password protected sharing, ensured that all netbios in the registry settings are correct. Pings between them are inaccessible returnded.
Any help would be appreciated.
Thank you!
Hi Jonathan,.
I see that you two computers on the network cannot see each other. I'll help you with this problem.
1. don't you make changes to the computers?
2 are computers on a domain network?
3. do you have a router connected to these computers?
Method 1:
Open the HomeGroup troubleshooter
http://Windows.Microsoft.com/en-us/Windows7/open-the-HomeGroup-Troubleshooter
Method 2.
Make sure that the following services are enabled on the computer.
(a) click Start, type "services.msc" in the search and click on services. Verify that these services are enabled:
-TCP/IP NetBIOS Helper service
-DNS Client
-Function Discovery Resource Publication
-SSDP Discovery
-UPnP device host
To start the service and set it to automatic, follow these steps:
(b) right click on each of the services listed above and click Properties.
(c) click the general tab, and then, next to startup type, select automatic.
(d) click on apply and then click Start.
Method 3.
I suggest you follow the steps in this article.
Enable or disable network discovery: http://windows.microsoft.com/en-US/windows7/Enable-or-disable-network-discovery
Method 4:
Why can't I connect to other computers?
http://Windows.Microsoft.com/en-us/Windows7/why-can-t-I-connect-to-other-computers
Refer.
Homegroup:
http://Windows.Microsoft.com/en-CA/Windows7/products/features/HomeGroup
Let us know if you need assistance with any windows problem. We will be happy to help you.
-
515E - host on VLAN may not leave
Hi all
I have a restricted license, the PIX 515E 6.3 (4) running. 2 physical and logical interfaces 1 (Vlan20). The movement of the inside to the outside and inside to Vlan20 works very well. Set up a domestic test Web on Vlan20 and can host server access without any problem. HOWEVER! Hosts on Vlan20 cannot send or receive through the outside interface! I'm dying here...
It's my current config. Thanks in advance.
P.S. I'm not using non routable IP. Two subnets are public.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Result of the firewall command: "sh run".
: Saved
:
6.3 (4) version PIX
interface ethernet0 100full
interface ethernet1 100full
logical interface ethernet1 vlan20
ethernet0 nameif outside security0
nameif ethernet1 inside the security100
nameif vlan20 security20 1st2ndfloor
activate the password * blah * encrypted
passwd * blah *.
hostname PIX
domain uberblah.net
fixup protocol dns-length maximum 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol 2000 skinny
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
names of
1st2ndfloor_access_in ip access list allow a whole
pager lines 24
opening of session
Outside 1500 MTU
Within 1500 MTU
IP address outside aaa.eee.127.66 255.255.255.252
IP address inside aaa.eee.45.1 255.255.255.128
IP address 1st2ndfloor aaa.eee.51.1 255.255.255.128
alarm action IP verification of information
alarm action attack IP audit
PDM location aaa.eee.45.95 255.255.255.255 inside
PDM location aaa.eee.45.100 255.255.255.255 inside
PDM 200 debug logging
history of PDM activate
ARP timeout 14400
NAT (inside) 0 0.0.0.0 0.0.0.0 0 0
NAT (1st2ndfloor) 0 0.0.0.0 0.0.0.0 0 0
Access-group 1st2ndfloor_access_in in the 1st2ndfloor interface
Route outside 0.0.0.0 0.0.0.0 aaa.eee.127.65 1
Timeout xlate 03:00
Timeout conn 01:00 half-closed 0:10:00 udp 0: CPP 02:00 0:10:00 01:00 h225
H323 timeout 0:05:00 mgcp 0: sip from 05:00 0:30:00 sip_media 0:02:00
Timeout, uauth 0:05:00 absolute
GANYMEDE + Protocol Ganymede + AAA-server
AAA-server GANYMEDE + 3 max-failed-attempts
AAA-server GANYMEDE + deadtime 10
RADIUS Protocol RADIUS AAA server
AAA-server RADIUS 3 max-failed-attempts
AAA-RADIUS deadtime 10 Server
AAA-server local LOCAL Protocol
Enable http server
http aaa.eee.45.95 255.255.255.255 inside
http aaa.eee.45.100 255.255.255.255 inside
No snmp server location
No snmp Server contact
SNMP-Server Community public
No trap to activate snmp Server
enable floodguard
Telnet timeout 5
SSH timeout 5
Console timeout 0
dhcpd address aaa.eee.45.40 - aaa.eee.45.50 inside
dhcpd dns aaa.bbb.101.10 aaa.ddd.201.10
dhcpd lease 345600
dhcpd ping_timeout 750
dhcpd field uberblah.net
dhcpd allow inside
Terminal width 80
Cryptochecksum: * blah *.
: end
The only other thing I can think is the possiblilty that, since you are not using a NAT at the address which is routed through your router upstream to is you have a routing problem there. If your upstream neighbor does not route these addresses to your pix that COULD be your problem. You could try the pat to see if it solves your problem and which would indicate that there is a routing problem.
-
the host catalyst application does not work
the host catalyst application does not work
Could be malicious. See this thread.
-
two PID.vi effect each other or not in the same program?
Hello!
I know that the PID.vi can be used in a multi-channel manner, and controls of this case different PID do not distrube each other. What if I use the same loop PID.vi two s to control two independent processes? They will be the effect each other? I want them to work independently, how can I handle this?
Thank you!
If they are reentrant, each instance in the schema will work independently and is want you want. No changes are necessary.
(Do not change system screws or things will break up with the next update of the software )
Maybe you are looking for
-
Computer HP laptop do not recognize the storage of my slate
Hello A few days back one I plugged my slate 7 on my laptop and the storege internal and sd card appear as usual on windows files. But not the second time. The laptop recognize the 7 slate but it appears as empty and I do not see the storage disk, i
-
I'm a new MAC user. I'm trying to print an excel worksheet. It prints with a small font and is not readable. How can I increase the font for printing. Is there a preview before printing? I could not find.
-
Extension of the network - Novice needs help
I'd appreciate some tips with a change I need to do to my wireless network. I have now works well, but I am somewhat a novice to this. My current network is composed of two computers. Computer A is a desktop computer connected to a router WRT54G2 wir
-
Is it possible to install the DSO on a Windows Client to perform remote Administration? I installed HIT 4.7.1 on Windows 8, but lacks the DSO.
-
Windows 7 is very slow to load and run programs
When I load Windows 7 it takes 3-5 minutes until the desktop. It then takes another 2 1/2-4 minutes for the icons to load and other programs to be active. Also, when you access my IP (AOL) it takes more than three minutes to load the program and to e