File sharing across 2 PIX 501s with NAT



I have a LAN (10.10.50.0) behind a PIX 501 (PIX-01) with all internal
machines NATTed to the outside IP as a Pooled address. Across the hall
I have a server stack (192.168.200.0) behind another PIX 501 (PIX-02)
with static NAT addresses to each server. The 2 PIX boxes are
connected across a hub. The outside addresses of the 2 PIXes are
public addresses on the same subnet.

I want the LAN machines to be able to access file shares on the servers
in the stack. So I opened PIX-02 to all incoming traffic on all ports
for packets originating from the PAT address of PIX-01. PIX-01 is
completely closed to incoming traffic.

This worked OK, but the file sharing has intermittent problems. For
example, in the middle of copying a bunch of files from LAN machine A
to server B, the process dies with a message that the network
destination is no longer available. Also, some file types (ArcView
..mxd files) had frequent errors when opening (but still intermittent).

What am I missing? Please don't suggest a VPN (;->) as I already tried
that and, while it solved the file sharing problems, it is abysmally
slow.

Thanks for any help!

John H.

.



Relevant Pages

  • Re: Help with long term network problem
    ... Symptoms were not finding mapped network drives or shared printer on ... DATA by other machines on the LAN. ... dispensing with the dedicated server and just using on as file ...
    (microsoft.public.windowsxp.network_web)
  • general vlan questions
    ... PIX 506 at 6.3. ... I am curious about VLANS (I'm not a network admin, ... a DMZ subnet, a wireless subnet, and a subnet for a group ... I do not want the guest machines to ever reach the inside ...
    (comp.dcom.sys.cisco)
  • Re: Home computer network problem
    ... I tried rerunning the network setup wizard but when I applied LAN setting it finished the wizard. ... Still if anyone feels they can offer more simple instructions to allow me to fix this & so share folders over my home network I would again be grateful for your help & will give it another try! ... I don't recommend either McAfee or Norton so don't have those programs running on any machines; therefore, I can't check the exact location of those configuration options for you. ...
    (microsoft.public.windowsxp.network_web)
  • Re: DSL Upgrade
    ... Discussions so far appear to be centered around hubs but since true hubs are just a means of connecting various machines on a LAN with no nat abilities they will not work in this case without the public id's mentioned. ... A router, Linksys BEFSR11, 1 port in and 1 out to your cable/dsl modem, or BEFSR41 with 4 ports, for your LAN computers, and 1 port out to your cable/dsl modem which will allow connection to 4 machines. ... If you connect 1 port for a LAN machine to a larger switch or hub more machines can be handled. ...
    (microsoft.public.win2000.networking)
  • Re: iptables firewall script for linux
    ... a canned firewall script will mostly protect me from ... I think of machines on my lan as workstations ... I decided to read at least 10 HOWTOs a week. ...
    (comp.security.firewalls)