internal web server access to the content of the network using the public ip address

Hi, I saw similar topics, but not a clear answer about it. I have a PIX 515e with two interfaces, a web server internal (ip 192.168.0.5) and internal users want to access the server by its (99.99.99.9) ie public ip address is not using DNS. Tried the command alias ' alias (inside) 99.99.99.9 192.168.0.5 "but does not work for http. I can access the server on the local network using the public address for smtp, pop3 and ftp with or without command alias, but not the http service. Any idea?

a few quick comments.

a function of the command "alias" is to force the pix to manipulate the dns response. However, you mentioned that you didn't use dns.

'alias' command will also force the pix to send traffic to 192.168.0.5 when it receives a packet from the inside and intended to be 99.99.99.9. However, since the host and the server are located in the same segment, i.e. pix must re - route the packet to the inside interface, and this operation is not supported with pix v6.x.

In addition, you mentioned the inside host can access the smtp, pop3 and ftp using 99.99.99.9. This is interesting because the host of 192.168.0.0 would not directly have access to the host of 99.99.99.x without router.

Tags: Cisco Security

Similar Questions

  • Force the url of the web server to hit the (slot) instance particularly jboss

    Is there a way we can force the url of the web server to hit the (slot) specific jboss instance? I remember that we can do in DAS from the drp port in the url of the Web server.

    Published by: 865729 on June 20, 2011 01:30

    This isn't the best forum for this question (you could get better results this announcement to the unduly JBoss: [http://community.jboss.org | http://community.jboss.org]), but I think that you can accomplish this by putting a dummy jsessionid in URL (at the first application so there is no jsessionid) and adding the jvmroute of the instance you want to hit. The jvmroute is what determines what roads of mod_jk instance demand so, theoretically, this should work.

    -George

  • Is it posible to the public ip address of the default locking?

    Is it posible to block the public IP address by default on multiWAN routers?

    I have several RV016 with up to 4 30Mbps Internet VDSL lines each and using the latest firmware to load 50-200 customer balance.

    When it is used for navigation, some sites will have to lock public source IP of the customer (especially sites that requires a user authentication).

    From a server point of view, public IP address will be between public IPs provided by ISP, automatic suite 4 round robin load balancing strategy.

    As public IP, read by the server changed server reduced session, users will need to enter username and password again to connect.

    Is it posible to lock this public IP for awhile to idle? (he has been featured on my old router BeWAN LX400H as "timer LockSource IP")

    ebarriera,

    The RV016 has no functionality like timer LockSource IP unfortunately. It's a common problem with load in the Cisco Small Business routers and key balancing mainly "secure them" traffic like HTTPS and RDP. I would test balance HTTP traffic and link HTTPS traffic to a WAN port and see if you get decent results.

    -Marty

  • Configure my VCSC with VCSe on the public IP address

    Hi guys,.

    I have a session of control VCS under my company Private IP and I my client on public IP VCSe.

    It will be possible to configure my VCSC with the VCSe after the configuration of the areas?

    The ports must be opened by my team of firewall in this scenario?

    Anything else I need to keep in mind.

    For the record, it is only for the objective test.

    You will appreciate any response.

    Thank you

    Saurabh

    > Then, practically there is no as such risk, and my client can use the public IP address on VCSe

    > without going to double network Option key. (which is used to secure more VCSe).

    Cisco highly recommend VCS-E deploy under the DMZ but it's true, too, many customers deploy VCS - E on public network directly.

    Please visit https://supportforums.cisco.com/thread/2154738?tstart=150 for more information security VCS.

    Next version of the plan to be supported VCS X7.2 software build - in the characteristic basic firewall, which allows configuration to allow/deny list based on the IP / port / protocol which should contribute to better security level or even VCS-E deployment on the public network directly.

    > So, I'll ask my client just buy a public IP address, that's all, and we are ready to go?

    A public IP will demand on VCS Expressway, VCS control can be use the NAT address glow (IE share internet access of the network of offices).

    You must also SRV DNS management (if small deployment probably better to use the external DNS service, there are a lot of company provide a service the two service also responsible DNS hosting and as free service).

  • ASA 5510 VPN - using a public IP address for the local network

    Hello, I have a problem which is probably very simple, but I can't seem to understand.

    I set up a site IPsec connection to another with a company, something I've done many times before without a problem. I use ASDM to configure this, because it is quick and painless, usually.

    We have one number of other site-to-site currently configured connections and works very well on this ASA, these are configured with the "Protected network - LAN" configured with the IP private of hosts within our network, we want to make available through the separate tunnels. This includes the configuration setting on our ASA for each connection to "guests aside ASA exempt from NAT.

    With this new link, however, the company asked us to use a public IP address for the host that we want to achieve through the tunnel. I don't know why, but they demand it. So I added a NAT rule for inside the host and set up the connection with the public IP address under "Local network". During the test to try to reach a host to their side, the tunnel didn't even try to open.

    What is the method here? I don't see where I'm wrong. I'm guessing that the 'host side ASA exempt from NAT' does not require for this, how if the ASA would know which internal host is the public IP address.

    Any ideas?

    Hi Leo,

    The steps are:

    1. Add the policy rule NAT for the specific host.

    2 - define the IP NAT as your LOCAL NETWORK address in the encryption settings.

    3 make sure that there is no rule NAT exempt for this host to the specific destination.

    What happens if you run a package tracer?

    Thank you.

  • How can I hold the public IP address on a specific profile on the asa 5510

    Hi guys

    How can I hold the public IP address on my session NAT VPN cisco customer for no one else can use it? I have a cisco ASA 5510

    the Interior is 172.10.20.86

    public 166.245.192.90

    Need to call my ISP?

    Thank you

    Sorry to say but your qustion is not very clear. Can you please post what you are trying to achieve?

    Thank you

    Ajay

  • Telepresence Content Server: Dissemination to the Public and private users

    *****

    Infrastructure:

    TMS 14.5 (private network)

    VCS - C 8.5.1 (private network)

    VCS-E 8.5.1 (Public network)

    S5.3 TCS (private network)

    Codian: Supervisor 8500, MSE 8510, 8321 ISDN (private network)

    *****

    New to this, so I don't know what would be the best way to do this, but basically the goal is to broadcast videos of TCS to the users of the network internal as live audiences without security problems. Try to do this without an external broadcast service.

    It is the State that works very well for internal users, but is not available to public users because it's on a private network.

    Any help is greatly appreciated.

    Thank you
    Mike

    You will need to provide public access to your Cameras, you can consult the administration of CHT Guide for a list of ports. We have our TCS on a private network and have the lanes of traffic through the network load balancers that rely on the public network to provide all access public and private.

  • Configureing Web server after installing Essbase on a distributed environment using the standard deployment methodology

    Hi all

    We have installed Oracle EPM (11.1.2.3) on an environment (Dev), distributed according to the standard methodology.

    On the first server we have foundation setup, aps, eas and on other servers (rest 5) we have setup an essbase, eis and studio alternately (Essbase transit all servers except on foundation server)

    As mentioned in the installation/configuration documentation we have run the configuration of websever on all servers and finally he ran on the server of the Foundation.

    There was no problem of erros/experienced in setting up however we would like to understand why we need to configure the Web server (on server 1 that has services of the Foundation) every time when we install products not based on the Web (Essbase, EIS and studio) on other servers... My question may sound silly but I'm confused, because these products are not accessible on the web.

    In addition, we also want to understand if we can monitor essbase services similar to the Foundation, aps and eas on the weblogic administration console.

    Based on my understanding, I guess we cannot monitor essbase server process on weblogic, however if it is possible to montior please let us know the procedure...

    Thanks in advance.

    Concerning

    krishnatilak

    Hi Krishna

    You do not have configure it once again if you have installed only EIS and Essbase later.

  • How to publish your site to one web server (other than the Business Catalyst)

    I want to know how to publish my site by uploading files to a web server Godaddy when I click on publish the only option I have is to use Business Catalyst, I want to use my Godaddy hosting and my own domain name.

    Thank you for your help.

    Carmen

    Hello

    As I know, the version you use for Adobe Muse is 1.1 which is an older version of Muse.

    This feature has been added in the latest version of Adobe Muse.

    I would you please uninstall Adobe Muse from your computer user n suggest the link below and download and install the latest version of Adobe Muse on your computer:

    Adobe Muse for Mac: http://www.adobe.com/go/muse_latest_mac

    Adobe Muse for Win: http://www.adobe.com/go/muse_latest_win

    I hope this helps.

    Kind regards

    Sachin

  • Web server plug in the configuration of Reporting and analysis

    Hi Hyperion gurus,

    Please suggest: -.

    at the time of Configuring Reporting and analysis (taken from Web server in the configuration of Reporting and analysis)

    What Web server I would prefer to use for planning and working space (Apache HTTP server/IIS HTTP Server) I'm having IIS installed on my environment.

    If you're suggesting IIS: HTTP Port?

    He suggested that if I select the Apache HTTP Server Port: 19000

    Somewhere I read the required planning installed IIS server that's why I'm confused.


    Thanks for the reply in advance...


    Thank you
    Kumar N

    Hello

    It is up to you what you choose, most people go with the apache plugin and would go for this one, it is much more robust and rarely there at - it problems with it. The apache option will install all necessary files.

    You've probably read that you needed IIS to use EPMA.

    See you soon

    John
    http://John-Goodwin.blogspot.com/

  • [View 5.3] Connection to security through Blast Server redirected to the Local IP address private view Desktop in Google Chrome

    Hello

    I am currently facing a questions in my test harness which happens when I connect to public IP address on server security by the breath. No problem if I connect using view Client.

    Using the breath, I can log on, select a desktop view, then the url of the Web page showing my ip Server security for about 10 seconds and then I was redirected to the private IP address of NAT from the desktop view target and of course I couldn't connect.

    vd.png

    Note: The local private ip address redirection does not happens if I configured to connect to show the connection to the server through breath.

    I have:

    • Self-signed SSL installed without warnings
    • activated the tunnel to connect to the server
    • Tunneling on server security enabled
    • disabled all firewall for testing purposes
    • locally defined in the host file to resolve my domain name full of security server static IP used in my office. (vsecurity.icliq.com in this case)
    • required ports are configured with port forwarding in my router from office

    security.png

    I hope someone could throw some light on this issue. Thank you


    Eddy

    Yes, the option of Blast Secure Gateway is used to ensure that Blast connections are routed from your browser by the server security (or connect to the server). That's what you want to access remotely. If you do not select this option, Blast connections will be direct to your virtual desktop. This is for internal connections.

    It goes the same for PCoIP and PCoIP Secure Gateway.

    Mark

  • EBS 12i on Cloud server with the public IP address but no DMZ

    Hello

    I installed Oracle EBS in a server (such as AWS EC2) cloud with a public IP address. I'm simply looking for personal learning and knowledge about security risks. As there is no given production safety is not serious at this point.

    Also, I don't mean to enter the configurations of the DMZ at the moment.

    I am able to access APPS internally under the server on port 8000 with URL http://<server:8000>/OA_HTML/AppsLogin. but I'm unable to access the URL above on internet.


    The environment is EBS 12.2.0 on Oracle Linux 5.11.


    I tried the options following, but so far without success.

    1. I tried to completely disable the Linux and SELinux firewall on the server. I have also authorized above URL in my personal office. So the 8000 port is not blocked anywhere.

    2, I followed this note to try to set it up on port 80, but still without success-> configuration Oracle E-Business Suite Release 12 on Amazon Cloud Infrastructure (Doc ID 1205963.1). But you should know that mine isn't on AWS EC2 but similar model.

    So simple question is how can I access front-end EBS on internet (DMZ) using port 8000? I do need to update httpd.conf of EBS Webtier (besides point 2 above)?

    Any help will be greatly appreciated. Thank you.

    See you soon!

    Gray

    Hello

    I discovered that I was using the CDN was blocking port 8000. So when I bypassed the CDN, then I could manage to access the URL with the port 8000.

    Thanks a lot for your help on this one.

    Concerning

    Gray

  • Internal untrusted clients directed to the external IP address for traffic PCoIP

    I have a network segment disable my firewall for some untrusted clients. When untrusted clients connect to view (5.3), they use a DNS name that resolves to a DMZ (view Security Server) host. That's where I think the problem is: it seems that security server responds with its external IP address, and then all the PCoIP traffic is routed to my router (where the external IP address can be found), then back into view and the customer. Traffic of SSL connection works fine, the traffic remains inside and does not get directed to the external IP address. It is only the PCoIP traffic that gets invited to use the external IP address.

    It seems that DNS is not enough - Security Server seems to respond and connect using only the external IP address configured in the external URL field PCoIP - is this correct? If so, then to do a substitution for the external URL so that internal untrusted traffic doesn't get routed the external IP address - this creates a lot of unnecessary traffic, mess with QoS, etc..

    Another idea would be to allow untrusted clients to connect directly to a login server instead of sending them on the Security Server, but I don't think that it is a best practice...?

    Mike

    As Linjo says the simplest solution is to set up a server for additional security to point these clients (no need of another server connection, you can pair it with the existing one). Today, you are required to provide an IP address for PSG, so if you need to send it to another, you will need a second server.

    Of course, if they are completely not reliable customers, then you can force through the external access point still but looks like you need avoid the cost of additional traffic from this approach.

    Mike

  • Restrict the public IP address of Source-based ASA 5500 VPN remote access

    Hello

    Please clarify my doubt below

    is it possible to restrict access to remote VPN to ASA based on the IP public Source, if yes how?

    Here is not the VPN filter under group policy. I want to restrict access from the indicated source IP (public IP)

    Thanks in advance

    Anoop

    Hi Anoop,

    This discussion will do it for you:

    https://supportforums.Cisco.com/thread/2027600

    Kind regards

    Julio

  • External access to the public methods of SWF

    How I acceding a load in the public methods of swf files in my main swf.

    var temp: ExternalSWFLoader = new ExternalSWFLoader ("FX_Ticker.swf");

    temp.x = temp.y = 0;

    Ticker = (Sprite) (temp);

    Ticker.y=stage.stageHeight/2 - Ticker.height - 20;

    mcBackground.addChild (Ticker);

    temp = null;

    Ticker.publicMethod () does not work.

    No problem.

    If you cast like a leprechaun, you can't access anything except the properties and methods defined in the sprite class, because the sprite class is static. Whereas, the movieclip class is dynamic and you can create and reference the properties and methods that you create.

    Thus, using the class sprite in as3 looks a bit by using the button in as2 class: there is nothing from the button class can do that the movieclip class can't do, and there are a lot of the movieclip class can do that the button class can not do. and in as3, there is nothing that the sprite class can do that the movieclip class can not do, and there is a lot that the movieclip class can do that the sprite class can not do.

    and the additional burden of the use of the movieclip class when the class sprite or button will work is negligible.

    If your external swf document class extends the sprite class, your swf file is a leprechaun and cannot be upcast as a movieclip.   because you can convert objects to the bottom (in the inheritance chain), you can convert a sprite in a displayobjectcontainer, interactiveobject or eventdispatcher displayobject or or object (and probably others I forgot).   but the lowest of the string you want, you will have less features.

    Bottomline: use the class movieclip as your document class.  There is no downside and plenty of upside.

Maybe you are looking for

  • Equium A100 upgrade to Windows 7, but now no sound

    Hello I have recently upgraded to Windows 7, but since then have no sound.I checked that all devices are active and not cut.I visited the sites of Realtek and Toshiba and downloaded the latest version of the software recommended by Toshiba, but still

  • presacrin c700 temp problem

    After I cleaned the comp, the temp whent down, but I think that's not recomeded level. I use "fan speed". hd0 37 c Temp1 55 c Core 0 52c Windows 7 ultimate 32 bit only firefox running. any suggestions?

  • X 1 carbon drop WiFi 5 GHz

    On my new X 1 carbon, with a new router Netgear R8000, the X 1 will not hold free wifi, even 3 feet from the router. There is a lot of intensity of the signal on all 3 channels. It connects for a while, but the icon turns then to 'limited', and I hav

  • Mouse travel Dell BT MIA

    My most old (2012-2013) BT travel mouse has stopped working on my Windows 7 Pro Inspiron 7110 machine and Dell is not listed under the mouse and other pointing devices in Device Manager.  The Intel Centrino Wireless Bluetooth 3.0 adapter and the Micr

  • Problem of Smartphones blackBerry syncing with iTunes

    When I open the software of synchronization of BB, a yellow warning triangle appears next to the heading on the opening screen music When I try to sync, it crosses the whole OK, but when I check the device there is no files? Anyone know what I need t