Hosts of inside do NOT speak to each other - Pix 506, Pix 515E

Good Morinig, everyone,

We have Pix515E and Pix506E, both are configured to pretty much the same: IP private networks inside, entering NAT for web/SSH servers for access. The problem is: inside hosts can not access these servers with NAT translation (cannot ping, cannot http, can't ssh). I thought that they are all the same network and will not affect the pix firewall, but why they don't communicate with each other? We used to use CheckPoint and never have such a problem for private network access intra-problem:

(a compendium see the running-config below): >

Result of the firewall command: 'show running-config '.

: Saved

:

6.3 (3) version PIX

interface ethernet0 car

Auto interface ethernet1

ethernet0 nameif outside security0

nameif ethernet1 inside the security100

names of

name 192.168.1.100 PrvEcommerce

name import 192.168.1.150

name 206.246.202.19 import-outside

name 209.96.203.2 gateway-cnf

the name 209.96.203.21 shark

name 206.246.202.22 SU-PC

name 192.168.1.50 su-pc

outside_access_in list access permit tcp any host 206.246.202.20 eq www

outside_access_in access-list deny shark host tcp everything

outside_access_in list access permit tcp any host 206.246.202.20 eq 3306

outside_access_in list of access permitted tcp 209.96.203.0 255.255.255.192 host 206.246.202.20 eq ssh

outside_access_in list of access allowed icmp all 206.246.202.0 255.255.255.0 echo

outside_access_in list access permit tcp any host 206.246.202.21 eq www

outside_access_in list of access permitted tcp 209.96.203.0 255.255.255.192 host 206.246.202.21 eq ssh

outside_access_in list access permit tcp any host 206.246.202.20 eq https

outside_access_in list access permit tcp any host import out eq www

outside_access_in list access permit tcp any host import out eq 819

outside_access_in list access permit tcp any host import out eq 3306

outside_access_in tcp access list refuse a whole

pager lines 24

ICMP allow any response of echo outdoors

Outside 1500 MTU

Within 1500 MTU

IP outdoor 206.246.202.18 255.255.255.248

IP address inside 192.168.1.1 255.255.255.0

alarm action IP verification of information

alarm action attack IP audit

location of PDM PrvEcommerce 255.255.255.255 inside

location of PDM 206.246.202.20 255.255.255.255 outside

location of PDM 192.168.1.200 255.255.255.255 inside

location of PDM 192.168.1.2 255.255.255.255 inside

location of PDM 206.246.202.21 255.255.255.255 outside

location of PDM 206.246.194.0 255.255.255.0 outside

location of PDM 209.96.203.0 255.255.255.0 outside

location of PDM 209.96.203.0 255.255.255.192 outside

location of PDM import 255.255.255.255 inside

location of PDM import-outside 255.255.255.255 outside

PDM bridge-cnf 255.255.255.255 out place

location of PDM 255.255.255.255 out shark

PDM location su-pc 255.255.255.255 inside

PDM 255.255.255.255 out SU-PC slot

location of PDM 10.1.1.0 255.255.255.0 inside

PDM logging 100 information

history of PDM activate

ARP timeout 14400

Global (outside) 2 206.246.202.57 - 206.246.202.62 netmask 255.255.255.248

Global 1 interface (outside)

Global (inside) 8 su-pc - 192.168.1.200

Global (inside) 4 192.168.1.10 - 192.168.1.240 netmask 255.255.255.0

NAT (inside) 1 192.168.1.0 255.255.255.0 0 0

public static 206.246.202.20 (Interior, exterior) PrvEcommerce netmask 255.255.255.255 0 0

static (exterior, Interior) PrvEcommerce 206.246.202.20 netmask 255.255.255.255 0 0

public static 206.246.202.21 (Interior, exterior) 192.168.1.200 netmask 255.255.255.255 0 0

public static 192.168.1.200 (exterior, Interior) 206.246.202.21 netmask 255.255.255.255 0 0

public static import import-outside (Interior, exterior) mask subnet 255.255.255.255 0 0

public static import (exterior, Interior) import-outside netmask 255.255.255.255 0 0

static (inside, outside) pc-su - SU-PC netmask 255.255.255.255 0 0

Access-group outside_access_in in interface outside

Route outside 0.0.0.0 0.0.0.0 206.246.202.17 1

Timeout xlate 0:05:00

Timeout conn 01:00 half-closed 0:10:00

: end

All suggestions and ideas are greatly appreciated.

Sean Chang

What IPs try internal users access? 192.168.1.x or 206.246.202.x?

I don't fully understand your situation, but your NAT Setup is very weird. I've never used "global (inside)..."

If users try to get to 192.168.1.x, try to remove these lines:

static (exterior, Interior)...

Global (outside) 2...

Global (inside) 8...

Global (inside) 4...

Tags: Cisco Security

Similar Questions

  • I'm trying to configure icloud with my pc/outlook.  I can not get the calendars and contacts in sync.  they do not speak with each other as they did when icloud was not enabled. Help, please.

    How can I configure icloud on my iPhone and a windows PC?

    Have you followed these steps?

    http://www.Apple.com/icloud/Setup/iOS.html

    http://www.Apple.com/icloud/Setup/PC.html

  • Can I allow an application for one person on my family share but does not allow for each other?

    Can I allow an application for one person on my family share but does not allow for each other?

    You can't delegate who has access and who doesn't have access to the applications. You can lock devices with age restrictions, so only items appropriate age are at their disposal. Or you can hide your list purchases. The purchased app can then be displayed when you want to share with someone else, then be hidden again once the application is downloaded on their device.

    I hope this helps.

    SI10

  • HA when ESX host are not equal to each other

    Hello

    Please, describe me my misunderstanding of HA...

    I have 3 servers ESX and 2 of them have 4 CPU 1 only have 2 CPU. I can create cluster HA with these 3 hosts, and if I can - how VM is migrated to ESX with 2 CPU, when one or two ESX with 4 CPUS will fail, in case when I have VMS with 4 CPUS per VM (even though admission control will be disable)?

    A vm with v 4cpus will not be able to be propelled to a host with only 2 physical processors. HA will not be able to failover in this case, even if the HA admission control is disabled.

  • My laptop computer and printer do not communicate with each other.

    I went to "printers and devices in the control panel and my laptop has an icon of troubleshooting beside him. I tried to search for updates/drivers solve the problem and nothing works.  It says ' unknown device is not a driver. My fax, copier and scanner work, but the printer does not work because there is a problem with my laptop. I could not use my printer because I was out of ink for 2 months, then I buy ink and now I can't print! Ink for a Lexmark is not cheap.

    I hope someone can help!

    Karen

    Because my printer is a Lexmark, I had to go to the Lexmark he site and search "Drivers" under which specific printer, you have it downloaded on my computer and loaded this way to connect my laptop with my printer.

  • VLAN SRP527W do not talk to each other

    Hello everyone,

    I'll keep it simple for the sake of the discussion.

    I have a SRP527W router that is connected to a switch L2 (a TP-Link... I know, it's not a Cisco...). and a PC and a printer connected to the switch. Now, I want to have the PC and the printer on 2 VLANS.

    I created 2 VLANS on the PSR (192.168.1.0/24 and 192.168.2.0/24) and I assigned the Lan 1 port at a time. The RPS is a DHCP server so I have SRP 192.168.1.1 and 192.168.2.1 installation provides IP addresses to the 2 VLAN.

    I have Setup VLAN 1 and 2 switch, 2 port assignment in the VLAN 1 and VLAN 2 3 port (port 1 is the trunk and connects to the SRP).

    When I start the PC and the printer they get their correct addresses from VLAN respective (PC: 192.168.1.30 and printer: 192.168.2.30) but for the sake of Odin, I can't see the printer from the PC. ESP was Inter VLAN routing active. Moreover, the switch has address 192.168.1.2

    What I am doing wrong?

    Thanks for the ideas, you can provide.

    -Mike * start things in the Office *.

    No problem at all, don't send me an email. We can get something set up maybe tomorrow.

    -Tom
    Please mark replied messages useful

  • Windows Vista & Palm Centro 690 do not talk to each other

    After my other phone went through the washing machine I changed to this Palm unit.  Active, came home and installed the synchronization software, worked well.  A few days later tried to synchronize again, no luck.  I'm working on for a few weeks trying to get it working again!  I talked to the local office of Verizon, they suggested that I talk to a technical support.  Them, spent more than an hour on the phone with them the uninstallation of the software, called again, download the new software, once again, still nothing, done a reset and a format and still nothing.  Have been using the Palm as a normal phone and that's fine.  I was unable to figure out what to do.  I even talked to Hp technical support, is not their problem! talk to the people of palm.  So here, I looked through your forms but did not find everything that is related to the Centro and Vista.  I'm almost ready to try anything that seems reasonable.

    Thank you, who finally did the trick, don't know what the difference is / was, but I don't like as it works again. Next time I try a synchronization, I'll try the front USB port and see what happens.  Gluton for the trouble I guess!

    Once again, thanks a lot for your help.  He is LARGELY APPRECIATED.

    kenz5103

    Message relates to: Centro (Verizon)

  • Microsoft 3000 wireless keyboards; they will interact with each other

    I have 2 PC and I would like to replace the wired keyboards for 2 sets of Microsoft 3000 keyboard, will they interact with each other and can I change Ch / Freq of the units

    Hi Baz,

    Each keyboard has different frequency and will not interact with each other.

  • Two Xbox 360 Wireless controllers Microsoft will interfere with each other?

    * Original title: Microsoft Xbox 360 for Windows wireless controllers... Two will interfere with each other?

    Controller: Microsoft Xbox 360 Wireless Controller for Windows (JR9-00011)

    Operating systems: Windows 7

    I have two PCs located in the same room. Is it possible to set up a wireless for each of them so that they do not interfere with each other?

    Hello

    I would like the links and see if it helps.

    How to set up your Xbox 360 to your Windows PC controller

    Set up your Xbox 360 for Windows gamepad

    If you have other questions, please post your request in the Xbox forums for assistance on this issue.

    http://forums.Xbox.com/

    Hope this information helps.

  • 2. separate menu which are unrelated to each other

    need to have 2 separate menu that are not related to each other

    Hello

    You can try the Menu manual. In this game you decide the sequence of each Menu item

    To activate the Menu manual

    • Create a menu in design mode
    • Click on Options (the blue circle top-right)
    • Select the type of Menu as manual
    • Then select the Menu item and click on '+' sign to add several menu items and customize according to your need

    If you're talking about something else then give use more details on what you're trying to do.

    Concerning

    Vivek

  • All network devices can see each other + Windows 7 computer, but machine Windows 7 can not see them

    Hello. Under the network of my machine Windows 8 folder, I can see all the devices on the network. This includes a printer, my computer Windows 7 (what I can access), an Apple TV (from special software), a wireless hard drive, the router and a digital recorder.

    The Windows 7 machine, I can only see the router and the printer. On special software, the Apple TV does not either. When you perform the Windows 8 computer host as a server for the special software, the Windows 7 machine could not see it on the special software. This means that there is something wrong on the Windows 7 this machine is not allowing him to detect other devices.

    In a game of LAN, Windows 7 and Windows 8 computers can't see each other.

    All devices are on the internet and I am posting this from the Windows 7 machine right now.

    Windows 7 and Windows 8 machine are on the same network.

    No device is on a host group and the group home service is disabled.

    Peer networking is enabled.

    Network discovery is turned on.

    Both connections are set to private/Home.

    Originally, the Windows 7 machine has been on his own home group and could be seen by anything. After a few hours, I finally got out of the home group, how other devices could see him then. However, he cannot always see other devices.

    How can I get the Windows 7 machine to see other devices? I am at a loss. Is there a service that I have disabled right now that needs to be enabled? I don't know what to do.

    Hello

    Please contact Microsoft Community.

    Disable the security software and check.

    http://Windows.Microsoft.com/en-in/Windows7/disable-antivirus-software

    Warning: Antivirus software can help protect your computer against viruses and other security threats. In most cases, you should not disable your antivirus software. If you do not disable temporarily to install other software, you must reactivate as soon as you are finished. If you are connected to the Internet or a network during the time that your antivirus software is disabled, your computer is vulnerable to attacks.

    Also check out the link below and check if that helps.

    Why can I not see other computers on my network?

    http://Windows.Microsoft.com/is-is/Windows7/why-can-t-I-see-other-computers-on-my-network

    If the problem persists, or you have questions about Windows, let know us, we will be happy to help you.

  • I have two computers in Windows 7 which will not each other on my network. All other computers will see and can share files, but they connect between them.

    My HP laptop has installed Win7 Ult, the Fujitus Win7 Pro.

    Both computers were sharing the files back, outside a residential group, for a period of time. One day, they are stopped. No changes have been made to computers. I tried a restore of the system on each of them, and it did not help. I re windows loaded on the HP and that did not help. I don't think that it is only a permission of the questions that I used a windows machine 7 third to map actions to each of the individual laptops using their respective IDs. I can transfer files from one of them the "machine in the middle", then the action of the other, or as a copy/paste between them directly.

    WSD and NetBT will not solve one machine for others, but all other computers on the network will dispay on each machine. Only, they refuse to see each other. I have disabled the firewall. Password protected sharing, ensured that all netbios in the registry settings are correct. Pings between them are inaccessible returnded.

    Any help would be appreciated.

    Thank you!

    Hi Jonathan,.

    I see that you two computers on the network cannot see each other. I'll help you with this problem.

    1. don't you make changes to the computers?

    2 are computers on a domain network?

    3. do you have a router connected to these computers?

    Method 1:

    Open the HomeGroup troubleshooter

    http://Windows.Microsoft.com/en-us/Windows7/open-the-HomeGroup-Troubleshooter

    Method 2.

    Make sure that the following services are enabled on the computer.

    (a) click Start, type "services.msc" in the search and click on services. Verify that these services are enabled:

    -TCP/IP NetBIOS Helper service

    -DNS Client

    -Function Discovery Resource Publication

    -SSDP Discovery

    -UPnP device host

    To start the service and set it to automatic, follow these steps:

    (b) right click on each of the services listed above and click Properties.

    (c) click the general tab, and then, next to startup type, select automatic.

    (d) click on apply and then click Start.

    Method 3.

    I suggest you follow the steps in this article.

    Enable or disable network discovery: http://windows.microsoft.com/en-US/windows7/Enable-or-disable-network-discovery

    Method 4:

    Why can't I connect to other computers?

    http://Windows.Microsoft.com/en-us/Windows7/why-can-t-I-connect-to-other-computers

    Refer.

    Homegroup:

    http://Windows.Microsoft.com/en-CA/Windows7/products/features/HomeGroup

    Let us know if you need assistance with any windows problem. We will be happy to help you.

  • 515E - host on VLAN may not leave

    Hi all

    I have a restricted license, the PIX 515E 6.3 (4) running. 2 physical and logical interfaces 1 (Vlan20). The movement of the inside to the outside and inside to Vlan20 works very well. Set up a domestic test Web on Vlan20 and can host server access without any problem. HOWEVER! Hosts on Vlan20 cannot send or receive through the outside interface! I'm dying here...

    It's my current config. Thanks in advance.

    P.S. I'm not using non routable IP. Two subnets are public.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Result of the firewall command: "sh run".

    : Saved

    :

    6.3 (4) version PIX

    interface ethernet0 100full

    interface ethernet1 100full

    logical interface ethernet1 vlan20

    ethernet0 nameif outside security0

    nameif ethernet1 inside the security100

    nameif vlan20 security20 1st2ndfloor

    activate the password * blah * encrypted

    passwd * blah *.

    hostname PIX

    domain uberblah.net

    fixup protocol dns-length maximum 512

    fixup protocol ftp 21

    fixup protocol h323 h225 1720

    fixup protocol h323 ras 1718-1719

    fixup protocol http 80

    fixup protocol rsh 514

    fixup protocol rtsp 554

    fixup protocol sip 5060

    fixup protocol sip udp 5060

    fixup protocol 2000 skinny

    fixup protocol smtp 25

    fixup protocol sqlnet 1521

    fixup protocol tftp 69

    names of

    1st2ndfloor_access_in ip access list allow a whole

    pager lines 24

    opening of session

    Outside 1500 MTU

    Within 1500 MTU

    IP address outside aaa.eee.127.66 255.255.255.252

    IP address inside aaa.eee.45.1 255.255.255.128

    IP address 1st2ndfloor aaa.eee.51.1 255.255.255.128

    alarm action IP verification of information

    alarm action attack IP audit

    PDM location aaa.eee.45.95 255.255.255.255 inside

    PDM location aaa.eee.45.100 255.255.255.255 inside

    PDM 200 debug logging

    history of PDM activate

    ARP timeout 14400

    NAT (inside) 0 0.0.0.0 0.0.0.0 0 0

    NAT (1st2ndfloor) 0 0.0.0.0 0.0.0.0 0 0

    Access-group 1st2ndfloor_access_in in the 1st2ndfloor interface

    Route outside 0.0.0.0 0.0.0.0 aaa.eee.127.65 1

    Timeout xlate 03:00

    Timeout conn 01:00 half-closed 0:10:00 udp 0: CPP 02:00 0:10:00 01:00 h225

    H323 timeout 0:05:00 mgcp 0: sip from 05:00 0:30:00 sip_media 0:02:00

    Timeout, uauth 0:05:00 absolute

    GANYMEDE + Protocol Ganymede + AAA-server

    AAA-server GANYMEDE + 3 max-failed-attempts

    AAA-server GANYMEDE + deadtime 10

    RADIUS Protocol RADIUS AAA server

    AAA-server RADIUS 3 max-failed-attempts

    AAA-RADIUS deadtime 10 Server

    AAA-server local LOCAL Protocol

    Enable http server

    http aaa.eee.45.95 255.255.255.255 inside

    http aaa.eee.45.100 255.255.255.255 inside

    No snmp server location

    No snmp Server contact

    SNMP-Server Community public

    No trap to activate snmp Server

    enable floodguard

    Telnet timeout 5

    SSH timeout 5

    Console timeout 0

    dhcpd address aaa.eee.45.40 - aaa.eee.45.50 inside

    dhcpd dns aaa.bbb.101.10 aaa.ddd.201.10

    dhcpd lease 345600

    dhcpd ping_timeout 750

    dhcpd field uberblah.net

    dhcpd allow inside

    Terminal width 80

    Cryptochecksum: * blah *.

    : end

    The only other thing I can think is the possiblilty that, since you are not using a NAT at the address which is routed through your router upstream to is you have a routing problem there. If your upstream neighbor does not route these addresses to your pix that COULD be your problem. You could try the pat to see if it solves your problem and which would indicate that there is a routing problem.

  • the host catalyst application does not work

    the host catalyst application does not work

    Could be malicious. See this thread.

  • two PID.vi effect each other or not in the same program?

    Hello!

    I know that the PID.vi can be used in a multi-channel manner, and controls of this case different PID do not distrube each other. What if I use the same loop PID.vi two s to control two independent processes? They will be the effect each other? I want them to work independently, how can I handle this?

    Thank you!

    If they are reentrant, each instance in the schema will work independently and is want you want. No changes are necessary.

    (Do not change system screws or things will break up with the next update of the software )

Maybe you are looking for

  • Computer HP laptop do not recognize the storage of my slate

    Hello A few days back one I plugged my slate 7 on my laptop and the storege internal and sd card appear as usual on windows files.  But not the second time. The laptop recognize the 7 slate but it appears as empty and I do not see the storage disk, i

  • printing excel spreadsheet

    I'm a new MAC user.  I'm trying to print an excel worksheet.  It prints with a small font and is not readable.   How can I increase the font for printing.   Is there a preview before printing?  I could not find.

  • Extension of the network - Novice needs help

    I'd appreciate some tips with a change I need to do to my wireless network. I have now works well, but I am somewhat a novice to this. My current network is composed of two computers. Computer A is a desktop computer connected to a router WRT54G2 wir

  • ASM of Client using?

    Is it possible to install the DSO on a Windows Client to perform remote Administration? I installed HIT 4.7.1 on Windows 8, but lacks the DSO.

  • Windows 7 is very slow to load and run programs

    When I load Windows 7 it takes 3-5 minutes until the desktop. It then takes another 2 1/2-4 minutes for the icons to load and other programs to be active. Also, when you access my IP (AOL) it takes more than three minutes to load the program and to e