I have PIX 6.1 and also 6.3 for testing.
On both I have three i/f: outside, inside, dmz
I am using DMZ only for connecting it to a router which establishes VPN with remote partners, so there are no public IP to be published on the DMZ i/f.
Traffic is flowing from inside i/f to dmz i/f to be then encrypted on the router, and vice versa.
I do apply nonat on the inside i/f for this traffic that is flowing to the dmz i/f.
My question is: do I also have to apply static?
I have read on documentation that I should, but I didn't do it and I can see everything woring fine, a parte from some messages sometimes saying "%PIX-3-305005: No translation group found for icmp src vpn:192.168.100.62 dst inside2:10.0.4.46 (type 8, code 0)
%PIX-3-305005: No translation group found for icmp src vpn:192.168.100.62 dst inside2:10.0.4.46 (type 8, code 0)
But any application tested worked.
What do I have to do?
Many thanks
Regards
Silvia
On both I have three i/f: outside, inside, dmz
I am using DMZ only for connecting it to a router which establishes VPN with remote partners, so there are no public IP to be published on the DMZ i/f.
Traffic is flowing from inside i/f to dmz i/f to be then encrypted on the router, and vice versa.
I do apply nonat on the inside i/f for this traffic that is flowing to the dmz i/f.
My question is: do I also have to apply static?
I have read on documentation that I should, but I didn't do it and I can see everything woring fine, a parte from some messages sometimes saying "%PIX-3-305005: No translation group found for icmp src vpn:192.168.100.62 dst inside2:10.0.4.46 (type 8, code 0)
%PIX-3-305005: No translation group found for icmp src vpn:192.168.100.62 dst inside2:10.0.4.46 (type 8, code 0)
But any application tested worked.
What do I have to do?
Many thanks
Regards
Silvia