Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

FWSM allow traffic in and out the same interface

Status
Not open for further replies.
Feb 26, 2009
12
CA
Hi,
My current setup.
I have a Cisco Router that has a def route of a FWSM. The Ethernet side of the router has 2 connections. FE0/0 to the LAN 192.168.10.0 and FE1/0 to a switch I have a dmz setup on.. call it 1.2.3.0. In the DMZ I have a web server that connected to the WAN and the web server is also on the 192.168.10.0 network.
I am able to access the web server from the public internet, but not from my internal LAN. I assume this is because by default Cisco does not allow traffic in and out the same interface.
FWSM supports the following and I tried these commands.
same-security-traffic permit intra-interface
same-security-traffic permit inter-interface
This did not work.

I am able to access my web server via LAN IP.
My DNS is public so there is no way to re-direct this traffic to the private side from the private side.

Any ideas? Am I missing something?
The above 2 are the only commands I have tried.

BTW. I am doing a nat exemption through my fwsm on the public ip of my web server.

Thanks in advance!
 
Have you tried:
- Using the alias command
- DNS rewriting
- Split-brain DNS

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Sure can:
DNS Doctoring:

Alias command:

Split-brain DNS (towards the bottom of the article [this is assuming the use of MS AD/DNS]):

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
The only problem with that is the internal ip of my device is for administration only.I really need to connect to the public side.
 
Has anyone successfully used the same security traffic command? Is there something else I can try to all ow this hairpinning? Getting desperate here.
 
BTW. I am doing a nat exemption through my fwsm on the public ip of my web server.
Can you post this??

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
your NAT exemption rule(s)

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
here is my actual nat exempt rule. I am exempting a entire /28

access-list inside_nat0_outbound extended permit ip 216.x.x.208 255.255.255.240 any

Right now I am allowing any in bound traffic to my ip address. It is accessible from the outside but not from the internal LAN.
I have entered both commands.
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface

Do I need to add a separate nat exemption for my static ip in order to get this same security command to work or something?


Thanks!!!!
 
I have to ask why that is even in there?? Does your web server actually have a public IP assigned to its NIC??

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Ya my server has a public IP and a private IP. The public side needs accessed by the public and the private lan
 
Anyone have an idea try? Otherwise I guess I will have to get with Cisco Really want to avoid that
 
Why do you have a public ip address and a private ip assigned to the server? You should merely have a private ip and nat it to the public thru the firewall.
 
The private is only used for management of the server. That needs accessible from the entire lan.I would really like to keep the current setup, but if I need to run static Nat that's what I will do
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top