Hi all. Small update here.
We still have not hooked up the sniffer but hope to do so soon. The new news is, we've had a small brainstorming session in house and come up with a germ of an idea. Best as I can describe it, here goes.....
We do PAT'ing (Port Address Translation) on our PIX515E...
I did a clear xlate against the PIX515E and attempted connection with PC-A with IP-A and had no success.
I will have to wait for this weekend to try to set up the sniffer.
Thanks for all your assistance to this point Lambent! I'll let ya know how things turn out.
Yes, i tried IP-A on PC-b and PC-C. It did not work with or without the Bluecoat in place and active.
Developments:
I have spent some time on the phone with Bluecoat support and after a bit of tweaking to the config. we are now able to get PC-B and PC-C through to http://ic.gc.ca with the...
Not quite right.
Scenario 2 without Bluecoat:
Testing PC: PC-B
NAT public IP of PC-B: IP-B
HTTP access to ic.gc.ca: SUCCESS
Testing PC: PC-C
NAT public IP of PC-C: IP-C
HTTP access to ic.gc.ca: SUCCESS
The PC-C was NAT'ed to a 3rd IP address in our external range. PC-A and the rest of the...
We use M$ IE6 with all updates or Firefox 1.4.
The error we get is:
Page can not be displayed.
An interesting development this weekend....
We again attempted to troubleshoot the issue by removing the Bluecoat device from the path. the interesting thing that we noticed was, when we attempted...
For Hinesjrh:
I checked the logs after an attempt to http://ic.gc.ca and found the following 2 entries:
2005-06-10 12:05:48 185 "WORKSTATION ADDRESS" 503 TCP_ERR_MISS 1762 401 GET http ic.gc.ca - - - NONE "BLUECOAT ADDRESS" - "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.8)...
In response to Lambent: I attempted telnet to http://ic.gc.ca 80 . The screen goes blank with a flashing prompt waiting for input in the corner. I didn't really know what to do as I don't Telnet frequently. hitting enter just returned the same prompt. Tried typing helo and enter and then I see a...
In answers to your questions:
1) We have not used the 192.197.183.0/24 anywhere in our network.
2) That I know of, we do not have any issue contacting other sites.
3) We have a Bluecoat SG400 with Websense inline in the network. As I have noted in my posts higher up in the thread, for...
I am unable to reach http://ic.gc.ca .
The address in the 216.x.x.x range is a dsl address from Cavalier telephone that is attached to a card in the PIX that is designated as the DMZ interface. That card is NOT physically cabled to the rest of the network. We were, at one time, going to use it...
Zen;
We are able to connect to this site through a laptop with external dial-up access with no issue. This I would assume would indicate that it is not a port issue. (Just an assumption but, a safe one I think.) I would try the Netstat -an but I am unsure what it would indicate to me if I...
Here is the config from the PIX515E That I promised. I have purposefully obscured the private information however, if there is a piece that you need to complete the puzzle just let me know. Here goes:
domainpix# sh conf
: Saved
: Written by enable_15 at 11:05:16.462 UTC Sat May 28 2005
PIX...
Yes, it does resolve to cpddis-cluster.ic.gc.ca [192.197.183.209] from behind the firewall. All traffic is allowed out, as far as I know. Traceroute appears to fail from the PIX515E. The firewall logs, viewed from our syslog server, do not appear to indicate any issues as there are no entries...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.