Re: 2 PIXes with their interfaces sharing the same switch and on the same VLAN.
Marjan Naumovski <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Organization | Neotel |
| Message-ID | <[email protected]> |
Hi Rudy, Are the two pix'es connected in other way besides the wan? For example A "lan" and B "dmz" are in the same network. If they are connected via these interfaces that explains why changing the gateway works. If you enable nat on B "dmz" you should be able to connect to the server. On Sat, 2009-08-01 at 08:19 +0700, Rudy Setiawan wrote: > Hi all, > > I have some problem that I need some solution/advice :) > > I have two PIX'es > * PIX A WAN is connected to Provider A > * PIX B WAN is connected to Provider B > * PIX A inside interface has the IP address of 10.15.1.1 > * PIX B DMZ interface has the IP address of 10.15.1.2 > * PIX B inside interface has the IP address of 10.17.1.1 > * Subnet mask for all of the IP addresses 255.255.0.0 or /16 > > I disabled nat by way of nat 0 access-list to both PIXes and the > interfaces as well (except the WAN). > I have a "ip permit any any" applied to all interfaces except the WAN, > > A user with IP 10.17.1.2 has a gateway of 10.17.1.1 is able to ping a > server in 10.15.1.10 (the server has a gateway of 10.15.1.1) but is > unable to ssh to the server. > But if I changed the gateway of the server to 10.15.1.2, then the user > is able to ssh to the server. > > What am I doing wrong here? > > Thank you so much in advance for the help. > > Regards, > Rudy > > _______________________________________________ > firewall-wizards mailing list > [email protected] > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards -- Marjan Naumovski System & Security Engineer ISP Neotel - Skopje [email protected] Tel: +389 2 5511 141 mob: +389 75 446 503