I did this same thing before between a cisco 804 isdn router and a pix 515. The end result of all my time, was cisco said that because the isdn router did not have a static address, and since the lan to lan tunels start at the pix that it would not work unless I got a static ip address. I...
What feature pack are you running?
ip/fw?
ip?
sure this can be done with the correct ios version. I would do this with th ip/firewall feature set and set up access lists as to what ports you wan open and apply the access list to the interface.
access-list 100 permit ip any 10.0.0.23 eq www
for...
choose checkpoint. It is the better firewall. It is alot more expensive to buy hardware and software wise, but all of the articles I have read always swayed me to choose checkpoint in the firewall area.
conduits are old school.
You should stay away from them in my opinion.
Basically you create an access list with any name and then apply it to the interface you wish to have it on.
Yes I am having the same problem. I have a pix 515r and a dmz with a win2k server on it. I can't seem to get dns either. I opened the same ports plus one other but was unsucessful. I also am having a routing issue where the dmz can see only the subnet directly connected to the trusted interface...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.