Hi all,
Hope you can help me.... I have a problem with PAT on a PIX 515. The configuration includes the following lines:
ip address inside 172.20.1.1 255.255.255.0
ip address dmz 172.25.1.1 255.255.255.0
ip address outside 192.168.1.2 255.255.255.0
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
nat (dmz) 0 172.25.1.0 255.255.255.0 0 0
static (inside,dmz) 172.20.1.0 172.20.1.0 netmask 255.255.255.0 0 0
static (dmz,outside) 192.168.1.4 172.25.1.2 netmask 255.255.255.255 0 0
global (outside) 1 192.168.1.3
route outside 0.0.0.0 0.0.0.0 192.168.1.1 1
The mail server on the dmz is receiving normally, and users on the inside netwok can browse any site but in some cases browsing at specific sites like they got a permanent "Not found" error. In other words, there is no traffic of any type from my inside network to those specific sites. Before this configuration, i have PAT on the router (192.168.1.1) and nat (inside) 0 0 0 0 0 with no problems. My dns is resolving correctly.
Browsing at cisco.com, i found the following:
"IP addresses in the pool of global addresses specified with the global command require reverse DNS entries to ensure that all external network addresses are accessible through the PIX. To create reverse DNS mappings, use a DNS Pointer (PTR) record in the address-to-name mapping file for each global address. Without the PTR entries, sites can experience slow or intermittent Internet connectivity and FTP requests fail consistently."
The ptr entries for the global address were created, but the problem stills.
Any suggestions?
Thanks in advance!
Hope you can help me.... I have a problem with PAT on a PIX 515. The configuration includes the following lines:
ip address inside 172.20.1.1 255.255.255.0
ip address dmz 172.25.1.1 255.255.255.0
ip address outside 192.168.1.2 255.255.255.0
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
nat (dmz) 0 172.25.1.0 255.255.255.0 0 0
static (inside,dmz) 172.20.1.0 172.20.1.0 netmask 255.255.255.0 0 0
static (dmz,outside) 192.168.1.4 172.25.1.2 netmask 255.255.255.255 0 0
global (outside) 1 192.168.1.3
route outside 0.0.0.0 0.0.0.0 192.168.1.1 1
The mail server on the dmz is receiving normally, and users on the inside netwok can browse any site but in some cases browsing at specific sites like they got a permanent "Not found" error. In other words, there is no traffic of any type from my inside network to those specific sites. Before this configuration, i have PAT on the router (192.168.1.1) and nat (inside) 0 0 0 0 0 with no problems. My dns is resolving correctly.
Browsing at cisco.com, i found the following:
"IP addresses in the pool of global addresses specified with the global command require reverse DNS entries to ensure that all external network addresses are accessible through the PIX. To create reverse DNS mappings, use a DNS Pointer (PTR) record in the address-to-name mapping file for each global address. Without the PTR entries, sites can experience slow or intermittent Internet connectivity and FTP requests fail consistently."
The ptr entries for the global address were created, but the problem stills.
Any suggestions?
Thanks in advance!