Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

inside to DMZ web server via Private(real) IP or Public IP. 1

Status
Not open for further replies.

dannyyo

IS-IT--Management
Dec 6, 2002
73
US
I have an issue of not being able to access the DMZ web server using the public IP. I can get to it using the private(real) IP, but not the public IP. However from the outside I can use the public IP to get to it. So I discovered that I can issue the command:

static (DMZ,inside) x.x.x.50 i.i.i.10 netmask 255.255.255.255

this will make it work. But now I can't get to the DMZ web server from inside using the private IP.

Basically, this is the same issue. Although the solution fixes one issue, but breaks the other.

I called cisco tac and they told me that I have to chose one and can't have both. Is this right? Not that I doubt TAC. I just want to confirm that everyone agrees with this.
 
You have to pick one. Do you use a DNS server or are you trying it by IP alone? If it is a DNS server, you can change the record on your internal server or use DNS rewrite to alter it when it hits the pix and it returns the fixed ip.


Brent
Systems Engineer / Consultant
CCNP, CCSP
 
I C. Thanks for clarifying it for me.

Currently, I'm only using IP. I'll add DNS to the equation later.

 
you can use private Ip using the ALias command. That was designed specifically for public webservers that need to be accessed internally.

IT Security news and information
In plain English
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top