Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Static NATs kill Internet 2

Status
Not open for further replies.

Speaker

MIS
Sep 5, 2001
72
US
I've done many static NATs on my company's PIX 515 5.3(1). Starting this past Friday, creating a new static NAT prevents the NATed maching from connecting to the Internet. It resolves the IP address, says "connecting to [WWW IP], then gives me a page cannot be displayed error.

If I remove the NAT and restart the PIX, Internet connectivity returns after about 10 minutes.

No canges have been made to the PIX beyond turning off logging last month when it started looping to a machine that was no longer on the network.

Current NATed machines are still able to connect to the Internet, but I haven't tried removing and re-setting the NATs for those machines because I suspect they'll stop working as well.

Any ideas?

TIA
 
HI.

You probably have a problem with the registered IP address.
Check the perimeter router configuration (or ask your ISP if they manage it). Maybe the address you're using is not legitimic, not routed to your pix, is the subnet broadcast address, has a dirty ARP, etc...

Try traceroute to that address from here:
How far can you get?
How far can you go with the other addresses?

Check the pix syslog messages (level 3 or 4), does the pix complain about anything?


Yizhar Hurwitz
 
You'll need to clear the arp cache on the PIX and the internet facing router.
 
I cleared the arp cache on the Internet router and that solved the problem of machines not being able to connect when the NAT is deleted.

I also found that I could ping the public address I was trying to assign, although it doesnt show up anywhere in any configs or documentation (we had another guy here who worked on WAN issues who may have done something with that address and didnt document it, but it doesnt show up in any configs, either).

Anyway, I'm still not able to NAT addresses, but at least I can undo the damage when trying. Thanks for the help. I'll have more time next week to keep plugging away at it.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top