CISCO PIX hard question, can you answer it? TIA



I am not a real Cisco guy and the person I use says that what I want to
do is not possible.

I know that someone smart person out there can figure it out.

I have a PIX FW, no DMZ, 10 users inside the FW and three servers
inside the firewall.

All the servers have static nats from the outside to the inside over
specific ports.

Host1.contoso.com 66.121.13.151 nat => 192.168.1.1 port 80, 443, 3389
etc.
Host2.contoso.com 66.121.13.152 nat => 192.168.1.2 port 80, 443, 3389
etc.
Host3.contoso.com 66.121.13.153 nat => 192.168.1.3 port 80, 443, 3389
etc.

My DNS server is inside the firewall host1.contoso.com

When a user attempts to connect to Host1.contoso.com from the outside
world they get an ip address of 66.121.13.151 and can connect to the
server/service

When a user from inside the firewall attempts to
http:\\host1.contoso.com they get the ip address of 66.121.13.151 and
cannot connect to the host.

I am told that it is a Cisco "feature" to not allow this type of round
trip IP connectivity.

I want to be able to have users connect to host1.contoso.com from
inside or outside the Firewall using the same DNS sever or the same IP
address 66.121.13.151.

I am sure that this can be done, but not sure where in the Cisco UI or
PDM to make this option work.

Thanks in advance

.



Relevant Pages

  • Re: Firewall Hardware and a bit of a Rant
    ... I need advice on which hardware firewall to purchase for a client with 20 users. ... I'm fairly new to SBS and have installed 3 servers. ... Watchguard seem to think they are Cisco and don't have to provide support to smaller IT guys because they are so powerful etc.. ... If my client didn't need web filtering, I'd bang a PIX in and use the Cisco VPN Client for remote access with local database XAuth to provide double authentication. ...
    (microsoft.public.windows.server.sbs)
  • IPTables and Natting question
    ... setup a iptables firewall to protect my LAN and Servers. ... The ketch is that I'm using my Cisco Router to do the Natting.. ... The last time i used a linux firewall it was a ipchains firewall using NAT ...
    (RedHat)
  • [SLE] BIND on SuSE 9 is trying to query unlisted servers
    ... I also have a caching DNS server on teh firewall. ... My firewall is set up to only allow outgoing DNS queries to the servers ... listed in root.hints and the two forwarders. ...
    (SuSE)
  • RE: Slow user logon on Terminal server after migration to Windows 2003
    ... The Terminal Servers are 2000 or 2003. ... "Inside the firewall zone" means that the Citrix Servers have a firewall ... available RPC ports? ...
    (microsoft.public.windows.server.active_directory)
  • Re: medical records, web server, & stateful firewall vs packet filter
    ... > image and SQL servers directly (the image server link in particular ... The image and SQL servers ... the 2 firewall layers should run different s/ware - the idea is that a major ... security always cost a lot more than you expect (this comes up whenever we ...
    (comp.dcom.sys.cisco)