Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

No internet through PIX 501

Status
Not open for further replies.

spudnuts

Technical User
Sep 30, 2002
123
US
I have two PIX 501's, for some reason one of my servers is unable to reach the internet and i'm at a lost as to why.

This server use to be in the DMZ but for security reasons, i've moved it into our intranet. I've updated all DNS servers for resolution and updated the ip's in the PIX.

access-list inside permit udp host [inside ip] any eq domain

access-list outside permit udp host [outside ip] any eq domain

static (inside,outside) [outside ip] [inside ip] netmask 255.255.255.255 64 64

nat is working fine, what am I missing? If you need anything else from the config just let me know.

Thanks

Information Assurance,CCNP,CST
 
I've run a ping from another server in the intranet and then ran "debug icmp trace" on the PIX. I can see translated and untranslated icmp echo's and replies. When I ping from the server that doesn't have internet, I get translated echo's but no untranslated replies. Any ideas???

Information Assurance,CCNP,CST
 
ping is not allowed from hosts behind the pix if you dont allow it with access-lists.

Can you post the entire config. If above is the complete access-list thats the reason you cant access anything.
You allow dns traffic but deny everything else from your lan if the above is correct.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top