Re: resource access behind PIX



In article <g98h44luq7o8f394vgrn7j0not5c1l89ki@xxxxxxx>,
Brian <see_footer@xxxxxxxxxx> wrote:
On a customer's test network, 192.168.1.0/24, they want to be able to test the
PIX ALCs to web servers on the same private range by accessing the public IPs on
the PIX (6.3(5)). I know by default the PIX doesn't allow this because of
possible spoofing. Is there a way to enable this?

No, there isn't, not with that PIX version. (And I would hypothesize
based upon the version number that the model involved is a PIX 501,
505/505E, or 520, and not a 515/515E or 525 or 535 that could be
upgraded to a newer version.)

In PIX 4/5/6, if you want an inside packet to access an inside
source via the public IP, then the packet must pass out the
outside interface and be re-written by something external,
such as "NAT on a stick" at the router level. If the packet is
not rewritten then the PIX will detect (at least for TCP) that the
packet is the same packet that went out and will silently drop
the packet.

There are a number of proxy services, such as TOR networks
("The Onion Ring"), which can be used to send out packets whose
payload would get sent back.
.



Relevant Pages

  • Re: [fw-wiz] Question about a Cisco PIX 515 - Routing question (I think)
    ... The PIX accepts the ... packet from the Internet, changes the addressing to map the ... It may be easier to get the servers ...
    (Firewall-Wizards)
  • Re: Connecting 2 networks via Win 2003 server
    ... The PIX will redirect the packet to ... (the RRAS router) because of the static route you added. ...
    (microsoft.public.win2000.ras_routing)
  • Re: Pix 501 Tunnelling problem
    ... You may also need to add the deny rule to your Crypto Access-List ... otherwise the PIX will still try to send the packets over the VPN. ... but the packet never exits the outside interface. ...
    (comp.dcom.sys.cisco)
  • Re: Pix 501 Tunnelling problem
    ... You may also need to add the deny rule to your Crypto Access-List ... otherwise the PIX will still try to send the packets over the VPN. ... but the packet never exits the outside interface. ...
    (comp.dcom.sys.cisco)
  • Re: Windows vs Cisco
    ... If PIX is not asked to handle some requests at application level (such as ... I agree that PIX has a better performance than the packet ... than the packet filter running on a UNIX system, ... ITShield Firewall can handle more than ...
    (comp.security.firewalls)