Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 515E Address Translation

Status
Not open for further replies.

GISD

MIS
May 22, 2003
31
US
We are using the PIX 515E w/ V.6.2. and we are using NAT for address translation. Long story short we are trying to allow outside access to a terminal server in our dmz but to no avail. We have opened port 3389 and we also have a static route translated. Now I know vpn would be the safer way to go but the powers that be have deemed it too time consuming and for that to be instituted at a later date. Any answers? B-)

Current config as follows:
static (dmz,outside) xxx.xx.xxx.xx yyy.yy.yyy.y netmask 255.255.255.255 0 0
access-list out_acc_in permit tcp any host xxx.xx.xxx.xx eq 3389
access-group out_acc_in in interface outside

x=public ext. ip
y=dmz ip
 
Can the terminal server access the outside devices (via ping)? Just trying to see int which direction the problem may be occuring.
 
Yes, the server can ping the outside devices.
 
If you go to something like what address does it say you are coming from ? is it the one you expected ? if not, try to issue a "clear xlate" on the pix, your nat table might not be reset after you made the changes to the static nat.

Jan

Network Systems Engineer
CCNA/CQS/CCSP
 
Funniest thing is that after searching the archives of this forum, there were suggestions regarding other situations that could indeed apply to my dilemna. I did indeed "clear xlate" yesterday and it shows an active translation for the Term. Server to the outside but testing it I am still unable to connect to it.

I ran ethereal on an outside connection and received this

xxx.xx.xxx.xx yyy.yy.yyy.yy TCP 3389 > 1202 [RST, ACK] seq=0 ACK=###########

Any other ideas???
 
Where are the rules for your DMZ interface? Ya gotta have those...otherwise nothing's gonna work.

A complete config would be a bit more helpful.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top