Hello all -
I am trying to establish an ipsec connection between a MS 2k3 Server in my dmz and a MS 2k3 Server on my inside network. I have tried the following setup with no sucess.
the inside net is 10.x.x.x and the dmz is 172.16.1.x
static (inside,dmz) 10.0.0.0 10.0.0.0 netmask 255.0.0.0 0...
KOPAR -
I would suspect the problem to be in this line of code on your pix.
access-list private deny tcp any range 3127 3198 any
I am assuming you are using this rule to block the payload in the NoVarg.a virus?
Good idea however, Windows cycles through tcp ports for different net requests...
Here is a cisco page that explains NAT Vs. PAT
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800b6e1a.shtml
Mix NAT and PAT Global Statements
"In this example, the ISP has again provided the network manager with a range of addresses from 199.199.199.1...
Actually if you only provide the pix with one ip for the global it will default to PAT.
Therefore, KOPAR you are correct.
Sorry I can't help you with your actual problem.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.