Replacement of the ALIAS statements

I am updating a configuration inherited at 6.3 and use PDM, for ease of maintenance. The configuration is a step 3 515, with servers face outwards on the DMZ.

The inherited configuration using ALIAS' are to allow internal users to access the servers in the DMZ using their global IPs rather than their local IP addresses. The ALIAS' are are also applied to the DMZ itself allowing a server DMZ talk to one another using IP Global of the latter. Statements of typical aliases for a given server would be:

ALIAS (INSIDE) 192.168.2.1 x.x.x.x 255.255.255.255

ALIAS (DMZ) 192.168.2.1 x.x.x.x 255.255.255.255

192.168.2.1 is the IP address of a server on the DMZ where x.x.x.x is the global address.

PDM does not support alias commands so I replaced the old statement with DNAT:

static (DMZ, inside) x.x.x.x 192.168.2.1 netmask 255.255.255.255

This method works fine to allow internal users to access the DMZ servers with their global IP address.

However I can't see how to apply this approach to servers on the DMZ.

Can anyone help please?

Looks like you have a very good understanding of the work of the alias command. Is not an easy thing for most people...

But I would point out an error in your post. My guess is the alias command is doing what we call "DNS Doctoring" destination NAT. Which means that as servers on the DMZ has a DNS reverse lookup for other servers on the DMZ, the DNS server responds with x.x.x.x. The PIX intercepted this answer and replaced the address in the answer DNS with 192.168.2.1 for servers on the DMZ could access other servers through their local address, and not the global address.

Make sense? Your first static is so perfect for destination NAT for internal users trying to hit the DMZ servers via their global addresses. To do this work for "DNS Doctoring" all you have to do is to add "dns" at the static (s) on the PIX you need to access from other servers on the DMZ. Using your address examples, something like this:

static (dmz, outside) 192.168.2.1 x.x.x.x dns netmask 255.255.255.255

Take a look at the Ref order here:

http://www.Cisco.com/univercd/CC/TD/doc/product/iaabu/PIX/pix_sw/v_63/cmdref/s.htm#wp1026694

I hope this helps.

Scott

Tags: Cisco Security

Similar Questions

  • replacement of the alias command

    I would use the MDP to manage my PIX. My config is currently using the alias command. Can I replace the alias with static controls?

    Thank you

    Alias of (internal) exodus 192.195.176.17 174.18.2.20 255.255.255.255

    In fact, the keyword "dns" on the second static shouln t be there. You need the 'dns' on the first static for hosts on the DMZ are the real IP and not the NATted in DNS answers. Make sure that you "clea xlate" after these changes, clear dns caches (ipconfig/flushdns on win2k/xp), and that there is not the host entries in the affected machines. For your configuration, you should have this:

    static (dmz, outside) 123.123.123.123 192.168.1.1 dns netmask 255.255.255.255 [keyword dns tells the pix to DNS doctoring for this translation because DNS resolves the public IP address]

    static (dmz, inside) 123.123.123.123 192.168.1.1 subnet 255.255.255.255 mask [allows the internal hosts to connect to the public IP found in DNS and it translates the private IP on the way to the demilitarized zone]

  • I need help to swap my iphone 6s I bought from the United States and I can't replace it here in India

    Hello Apple

    I bought an iphone 6s on the apple store in Tampa, Florida in December 2015 and it worked for a few months and then it started giving a problem that I remove the charger, the phone will of I talked to apple care him they tried every possible means to help me in restoring the software and all but however there seems to be a hardware problem , so for that I have to send the phone to an Apple store outside the India which is not possible for me because it is very expensive for me, this phone can be replaced in case India model number. its been a month now that I can use my iphone 6s, what should I do I need urgent help. on the purchase of the phone, they told me its guarantee in the world and can be replaced in India, but now he can't be replaced here please do help me with the same

    I'm sorry, but nobody here can help you. We are just other users of products Apple here. You must contact the Apple support and ask them about it.

    The warranty of the iphone, however, has never been international. He always included the clause that support may be limited in the country of purchase. I don't see any solution for you other than to exchange the defective unit in the United States.

  • CRASH: Replacement of the enumerations in the State diagrams can shoot down LabVIEW 2012

    Environment

    Windows 8 64 - bit, 32-bit LabVIEW 2012

    Steps to reproduce

    1. Open the attached draft
    2. Open Statechart.lsvc/Diagram.vi
    3. Double click on the blue Transition in the Middle, navigate to the guard
    4. Make a right-click on the enum constant-> replace-> select a VI...
    5. Choose 'Enum 2.ctl.
    6. 'Select the VI to open' dialogue box appears again. Reselect "Enum 2.ctl.
    7. Observe the first weird behavior: block diagram of the guard is replaced with the front panel of the enum
    8. Click on "Cancel".
    9. Double-click the blue Transition again. LabVIEW crashes here.

    Error messages

    I first encountered this in a large project with a complex of state transitions. This was the message indicated before the death of LabVIEW:

    With the small example that I have attached, there was no message at the time of the accident - LabVIEW just abandoned in silence. When I rebooted it showed (tested twice, same message):

    Hi JKSH,

    Sorry for the incorrect post, I was talking with one of my colleagues on this issue. I was able to reproduce this problem on Windows 7 32-bit and LabVIEW 2013 (32 bit). I filed a bug report (called the request for Corrective Action or CAR) on the issue. The number of CAR is 421985. You can use this to track when the CAR will be fixed because there will be a list of cars that are resolved in the release notes. I also wanted to put that workaround for this error is just to add the VI manually, then delete the original VI (instead of use the substitute function).

    Thank you for helping us find this bug.

    Thank you

    Best regards

    Bill

  • I want my country account will be replaced by the India in the United States that I have recently moved to US.

    Can someone guide me on how to change the country into account in the United States? I just move to US a month ago and my country profile keeps appearing as the India. I can't renew my subscription because of this.

    Our ID Adobe, payment details and you buy Adobe store must be attached to the same country.

    For tax reasons, it is not possible to change the country associated with an existing Adobe ID.

    To work around the problem, you can create a new Adobe ID to the e-mail address associated with your existing Adobe ID please see this document for instructions: change the country associated with your Adobe ID

    Concerning

    Megha Rawat

  • return to the United States with Israel-purchased HP Officejet 5610 - supply question

    Buy printer in Israel, there diet 230 - VAC.

    I'll be living in the United States - what should I do to convert the power supply?

    Get a new one for the States?

    Or is it more complicated?

    Yes, you could buy the power supply Q7310-6003 to the United States when you get back.  See http://h20141.www2.hp.com/hpparts/partsdirectory/buy.htm or Google for Q7310-60003.  Prices vary widely, I saw one for $ 100 and another for $30.  I also had good results by purchasing replacements from eBay.

    Also carefully check the power supply you have - suppleis most of our days have a 'universal' entry note, maybe it's that one that you already have work and you would need just to a new power cord.

    Kind regards

    Bob Headrick, MS MVP printing/imaging

  • Tecra M10 - 120 - my European warranty is not valid in the United States

    Hello

    I have a Toshiba - Tecra M10 - 12o laptop.
    This unit that I bought in Abu Dhabi, United Arab Emirates UNITED with 2 years international warranty extension.
    The warranty is still on, and now I am settled in the USA.

    Now, I'm having a problem with the LCD and want to have it repaired. I went to two suppliers of services authorized for Toshiba in New York, but after reviewing my system, they said that they are not allowed to fix it because it's a European model laptop.

    For the same problem, I had the LCD screen, replaced in Abu Dhabi, United Arab Emirates UNITED Toshiba distributor/service provider. But good as now I am in New York, USA and not able to get the correction of a problem here.

    Please kindly advice how to get this problem fixed so that in the United States for a laptop of model Europen.

    Thanks in advance.

    Kind regards
    Prasad

    Hello

    As far as I know and after the guarantee page ÉMAÉ Toshiba, Toshiba computers laptops, Netbooks and Smartbooks are covered by at least 1 year EMEA standard warranty, valid from the date of purchase.
    This warranty is applicable only in the EMEA region (Europe, Middle East and Africa)

    You can find more details here on this Toshiba European page:
    http://EU.computers.Toshiba-Europe.com/innovation/services/standard-warranty/

    Here you can find the PDF EMEA warranty info.
    http://goo.GL/wN1mS

    So if you're outside the region of EMAE and if you don t have bought additional warranty extensions, you will have to pay for the service :(

  • Satellite A300 - Can ASP deliever AC adapter for my address to the United States?

    Hello

    I have the international limited warranty on my laptop Toshiba Satellite A300... I am currently in India...
    My AC adapter / CC gave me hard to the ppl of support center said that they replace it... but it'll take 4-6 weeks to arrive from Singapore...

    Now my problem is that I go to the United States for studies and I'll be leaving in less than a week...
    They can provide the ca adpter in my place in the United States (or the service center closest to my place so that I can collect in the United States?... or can they redirect the adapter from the center of service in India or Singapore itself...)

    Please answer soon, his brother very urgent I

    Afonso

    Hi mate

    I m wondering why you post here in the forum
    How should - does anyone know what the ASP?

    You should get in touch with the people who would replace the AC adapter and should organize more details and handling

    In my opinion it's shouldn't be a big problem to send adapter to another address or country but you will have to bear additional cost

    This is my personal opinion...

  • My problem is that I bought apple tv 4th generation of the United States. now I want to use it in India, where it is common to 220 volts, but in the United States, it is common to 110 volts. Can I use the apple tv in India?

    My problem is that I bought apple tv 4th generation of the United States. now I want to use it in India, where it is common to 220 volts, but in the United States, it is common to 110 volts. Can I use the apple tv in India?

    BBought Apple TV USA for my children in Europe (220V).

    No problem, just replaced the plug

  • Pavilion 15-ab269sa: is it possible to replace just the screen on computer pavilion 15 laptop?

    Her half of my screen has become fractured (not physically) and can be used. However, through the half of the screen is fine, I was able to use the laptop normally and it seems that no other part of the laptop is damaged. So I was wondering is there somewhere I can buy a new screen or if it can be replaced at all? Thanks for any help!

    Altogether. I do it all the time. Where do you live (country)?

    This is a LED 15.6 inch 1366 x 768 display and will cost about US $65 if you live in the United States (or Western Europe) and we can provide a manual or a video for instructions on replacing the screen.

    BrightView, HD, flat 809371-001

    Here's one to the United Kingdom:

    http://www.eBay.com/ITM/new-15-6-led-notebook-screen-WXGA-glossy-HD-Panel-for-HP-Compaq-SPS-809371-001-/231673956710?hash=item35f0d80966:gFMAAOxyB9RS1VuQ

  • is there any replacement of the computer motherboard laptop dv5 pavilion?

    I have a pavilion dv5 laptop. My father bought in the United States. but I've only used for 3 months. When I sent it to a technician, they told me that my laptop is already irreparable due to problem of Council. I don't know what that means. is there any replacement motherboard or is there a chance for my laptop be fixed.

    Hello

    Please visit the page #92 this book to get the right one.

    h10032.www1.HP.com/CTG/manual/c01550108.PDF

    Kind regards.

  • Material of restoration to the original state of the manufacturer will make legitimate recovery discs work?

    Hello.

    Back story:
    I tried to create a system to dual-boot with Windows XP and Windows Me on a PC from Hewlett Packard, model a350n, to facilitate access to the old and more recent examples of software in my computer.  Operating systems that are installed properly, however, when running Windows Me, I noticed that the system has detected a large number of hardware problems and a number of missing drivers. I have no problems the first time I installed Windows Me, and I realized that this must have been the existence of partition recovery console Hewlett Packard, who was at the current time, where the Windows Me operating system can locate the necessary drivers for the PC to operate.  Since the deletion of this partition (which I foolishly declared unnecessary from there), problems of hardware in the BIOS, PCI slots, sound cards, etc. exist in abundance.

    Issue to be addressed:
    The main concern is this: I have no legitimate recovery CDs that I received directly at HP, but when I use them, even if they have worked in the past, I thought that the discs do not support my HP model.  I've made several changes to the hardware (for example, replace the graphics card, some CD-Rom drives, additional memory, along with other things).  Cancellation and so restore the material to the original state of the computer will CDs recognizes the HP model once more?

    Thank you very much!

    UPDATE: I tried to return the PC to its original state by removing the extra material and restore that which has been deleted.  We had another similar model of HP with similar CD - RW, CD - R and DVD - ROM drives, so I'm only 95% some that I replaced those that actually are came with this PC.  It would make a difference?  The result is that the recovery disks, which are legitimately HP, not home-made copies, and which were used successfully in the past in this same model, has not recognized the model of PC than they were designed for, even if they are a match.  This may be the cause?  And what can I do about it?  My backup files can be done quickly and efficiently, if I don't mind having to do something eventually destructive, as long as I get those recovery CD to do their job.  It is essential that I restore the PC to its factory condition.

    Thank you!

    Hello Taran_Wanderer,

    Unfortunately there is little that can be done on the side Microsoft.  It's HP to provide you with the disks appropriate for your machine model.

    You can look in an update of the BIOS from HP, but honestly, I don't know if this will have an effect on the question of whether or not the HP recovery disks will work.

    Best regards

    Matthew_Ha

  • the system state data can be contained in 2 different folders, e.g. Windows or host1

    Hello

    Recently, my computer was able to start and I had neglected to backup my data. While dealing with the Windows Recovery Console, I inadvertently added a folder called host1 to the system. I tried to replace and remove this folder, but could not. Currently, I'm trying to back up my data to the system state by using the Windows backup utility. What's weird, is that in the log file, "Host1" is listed under the file saved to the system state data. Previously, these data were in the "Windows" folder The content of two files seems to be identical. I need to get rid of unnecessary duplication in my system. The backup file size was more than 200 gb. Phew!

    Thank you

    Before deleting copy just the system folder windows.old + System32 files (these files contain most of the settings and drivers. (In the case where in the future you need a driver for a printer you have you can always point windows to find in these files) in a new folder on the C drive and delete the rest in the windows.old and the folder windows.old himself. You could rename the Windows folder and not the host1 because XP uses host1 as its new folder. This is where the operating system boots from. The old windows folder contains more data due to past use and all programs that you have installed since you had the PC.

    All the best

  • Customer service does not meet the United States relative to the Compact Z3 repair

    Hello and happy new year!  I was wondering if anyone has experience with sending in a Compact Z3 for repair/replacement under warranty in the United States.  I live chatted and called several times and I can't get any information on the status of my repair or when I get my phone back.  I wonder if you guys could get some advice on what to do next.

    My Z3 Compact suddenly started having battery problems (first similar to this: http://talk.sonymobile.com/t5/Xperia-Z3-Compact/Battery-levels-jumping-randomly-and-not-charging/td-... and then it stuck at 50% and no loading or unloading).  My phone is under warranty until 2017, so I called, got an RMA number and sent him into their repair center in Laredo, Texas.  He arrived on 12/14, and here's the problem: no one can give me an update as to what is happening.  Many cats live and e-mail gave no information.  After a week, I called their customer service line and they said he was being sent to a Manager, who was supposed to send me an email in the next 24 to 48 hours, but didn't.  After the second week, I called again, and it's the same thing (promised an email of a Manager, who I have not received).

    I was told at the beginning that since my phone is an international model, they may have to order parts and could not give me an ETA, but they said that most of the repairs are completed within 14 working days.  They had my phone for at least 10 working days now (and 2.5 weeks in total), and I really should hear a kind of update now.  I'm trying to be patient because it's the holidays and I'm sure their technicians to repair a bit of time off the coast, but some communication would be the bare minimum of acceptable customer service.  At the very least, if Sony does not include automatic updates, I should be able to get some info by calling, instead of this ridiculous evasive.

    What else can I do to get information on the status of my claim?

    I feel your pain. I had a similar lack of information when the screen back of my cracked Z3C randomly after 3 days of property. He was sent to Laredo. I never had an update... called at least twice to get an update and told me I would soon receive a response and how if yes or no the repair would be covered by the warranty.

    Two weeks past, and all of a sudden I get a box from Sony with my phone repaired on the inside. No updates, no notification, no nothing.

    TL, DR: expecting anything near decent service communication or client with this Sony repair center is little more dreaming.

    We wish you the best of luck...

    -Evan

  • Re: W700 - purchased at the Service of the United States in Germany

    Dear Lenovo Service:

    This mail is a customer very disappointed and angry of lenovo who owned several "ThinkPad" produced by the past both at work and at home.

    Well, this is my story - I ordered originally my W700 on 26 Nov 09. After of many calls/emails to Lenovo customer, the machine finally arrived on December 22, two weeks after the original delivery date (Oakland, CA, USA) not to mention that I had to cancel my flight/lodging the 17 in Germany which I had arranged before hand a tolerance of 9 days of delivery time would be appropriate. It turns out it was a bad management and cost me US $350 to reschedule my flight itinerary;

    On 31 December, I was on a flight to Germany for training of technique of 8 months. The third day after my arrival in Germany, the laptop screen is suddenly cleared and restart/connect to an external monitor both ended up a failure.

    So the next day (4 January), I called Lenovo in Germany Customer Service line and explained my situation and literally supplies to speed up the process (I had badly need for modeling 3D CAD to work); Guess what, the representative was told that he did not know if my warranty can be carried over to Germany since the original purchase was made in the United States. Including, I told her that I bought an additional 3 years international warranty and they should be able to verify with a small "click" with the mouse. on the contrary, it took them 5 days to get back to me telling me that the guarantee has been verified and MOST UNACCEPTABLE, they asked me to send the computer laptop for the filing of repair on my sense of the part I find time at the post office and have to pay for shipping... it is not how the company was performed in ancient times with IBM. In the old days, I would get an empty box delivered to my door the next day and everything I need to do is put my laptop in and picked up by the local courier. IT IS RIDICULOUS; This isn't how Lenovo should treat its customers; as a loyal customer of IBM/Lenovo for years, this isn't how you pay me back with...

    aside from the default screen/graphics card.

    1. the keyboard is terrible. Flexible, noisy and feels like a piece of cheap plastic
    2. the program kept sends me errors when I tried to burn the "Recovery DVD" (of course, it was until the system broke down and became completely devoid);

    To a valued customer of Lenovo (if you really want to say so), I would make the following requests:

    • have the laptop fixed as soon as possible;
    • replace the original keyboard with keyboard FRU42T3143;
    • provide a DVD of Win7/WinXP original;
    • reimbursement of my port (I'll include the receipt in the box of the future)
    • HAVE SOMEONE ACTUALLY ACKNOWLEDGE THIS MESSAGE AND RESPOND. (not too much to ask, isn't it?)

    Note of the moderator; subject edited for relevance

    senw, welcome to the forum,

    I'm sorry to hear that you have encountered problems. I'm not able to help you directly, but would like to offer the following as documents of information for you, if all goes well, he could ease your pain a little / or not, you will have to be the judge.

    • have the laptop fixed as soon as possible;

    You are invited to send your W700 to Geodis to Heppenheim; I have sent customers ThinkPad for them for almost 10 years and have never been disappointed by the level of service systems received, IMHO, they are excellent at what they do. The rule of thumb is 5 working days, including shipping to and back again.

    • replace the original keyboard with keyboard FRU42T3143

    I don't know if they will be able to grant this wish, but it is certainly worth asking explaining them your concerns. It's something that is unknown territory for me because the situation is, in my experience, never came.

    • provide original DVD of Win7/WinXP

    You can certainly order a set of recovery discs for your system that you have been unable to create your own. It may take some time because they don't have them in Germany and will be sent from abroad.

    • reimbursement of expenses of Harbour

    At least that an additional servicepak was purchased for "collect Courier' standard warranty in Germany called 'bring-in '; the customer is responsible for getting the system to the repair center. It of unfortunate for you in this case, but has been the standard procedure even when IBM ran the show. It is a zone where levels of service may differ from one country to the other.

    • HAVE SOMEONE ACTUALLY ACKNOWLEDGE THIS MESSAGE AND RESPOND. (not too much to ask, isn't it?)

    It is a peer to peer forum, where members try to help others. There are a few employees of Lenovo who help you here in their free time, but unfortunately, there is no guarantee that you will receive an official response.

    Concerning

Maybe you are looking for