|
 |
03-14-2003, 08:57 AM
|
#1
|
|
Low Bitrate
Join Date: Mar 2000
Location: Media, PA, USA
Posts: 100
|
Pix Question
I am trying to fix a problem on a functional Pix firewall. Only certain local IP addresses are able to access the internet. There are now more machines that need internet access than there are addresses that allow this.
I didn't setup the Pix originally, but need to find a way to give other addresses internet access. I tried calling Cisco, but they are charging like $500 for a contract before I can get support.
Anyone have any ideas about how to open up additional addresses, or somewhere that explains this?
Jeremy
|
|
|
|
|
|
Advertisement
|
Sponsored links
|
03-14-2003, 09:18 AM
|
#2
|
|
Raw Wave
Join Date: Apr 2000
Location: Surrey, UK
Posts: 2,129
|
I'm assuming that the firewall does NAT for outgoing traffic.
Does it have 1-1 NAT mapping set up for those addresses, or is NAT enabled for all internal addresses?
Are there firewall policies set up to block outgoing http traffic for many of the internal addresses?
Is there a limitation to the number of NAT leases possible at any time - ie, are the particular internal IPs that have external access dependant on who gets there first or are they always the same (fixed) IPs?
Rob
|
|
|
03-14-2003, 09:26 AM
|
#3
|
|
Registered User
Join Date: Apr 2002
Location: South Coast, UK
Posts: 437
|
What IP addresses are you using on the local machines?
The problem you have sounds more like you are using fixed internet addresses rather than NAT. Are you using a DHCP server to allocate addresses to your clients?
__________________
-------------------------------------------
(=========-) 99% complete
--------------------------------------------
AMD K6/2 500 @ 450mhz to keep heat and power usage down, 64Mb, slim CDrom drive, 64mb USB pendrive for MP3 transfer, 10Gb 2.5" drive for MP3, USB>RS232
All jammed in external CDROM drive case.
Kenwood KVC-1000r In-Dash LCD. x-10 MouseRemote. Destinator V2 Gps. DC-DC with onboard Shutdown controller.
----------------------------------------------
|
|
|
03-14-2003, 10:48 AM
|
#4
|
|
Low Bitrate
Join Date: Mar 2000
Location: Media, PA, USA
Posts: 100
|
All of the machines have static internal (192.168.1.X) addresses. I did not setup the PIX, so I'm not sure of the internal configuration. Picking certain static internal addresses will allow local network access, but not internet access.
There is a command (I think it was show localhost) that listed 8 internal addresses along with some statistical info. Using any of those 8 addresses allows both local network access, as well as internet access.
I could be barking up the wrong tree here, but from the output of the localhost command, coupled with problems accessing the internet from other internal addresses, that was my conclusion.
Does this shed any light on the situation? Thanks for the help so far.
Jeremy
|
|
|
03-14-2003, 11:07 AM
|
#5
|
|
Registered User
Join Date: Apr 2002
Location: South Coast, UK
Posts: 437
|
The machines that can access the internet, are they a continuous address range, or are they random:
example
192.168.1.1 - 192.168.1.8 all can access, anything above cant, or;
192.168.1.1 can, 192.168.1.2 cant, 192.168.1.3 can etc etc.
__________________
-------------------------------------------
(=========-) 99% complete
--------------------------------------------
AMD K6/2 500 @ 450mhz to keep heat and power usage down, 64Mb, slim CDrom drive, 64mb USB pendrive for MP3 transfer, 10Gb 2.5" drive for MP3, USB>RS232
All jammed in external CDROM drive case.
Kenwood KVC-1000r In-Dash LCD. x-10 MouseRemote. Destinator V2 Gps. DC-DC with onboard Shutdown controller.
----------------------------------------------
|
|
|
03-14-2003, 11:26 AM
|
#6
|
|
Low Bitrate
Join Date: Mar 2000
Location: Media, PA, USA
Posts: 100
|
They are random. If memory serves, it is something like .17, .20-.25, .27, .101
|
|
|
03-14-2003, 11:16 PM
|
#7
|
|
FLAC
Join Date: Jan 2002
Location: Chicagoland, IL
Posts: 1,738
|
I've never played around on a pix, or really any cisco stuff ($$$$)  but it sounds like it simply has some access filtering rule in place thats bound via ip. Id image theres a way to open it up to your entire subnet.
|
|
|
03-15-2003, 06:33 AM
|
#8
|
|
Low Bitrate
Join Date: Mar 2000
Location: Media, PA, USA
Posts: 100
|
That is exactly what I want to do, but unfortunately I have no idea how to do that. There are a host of commands you have to use, and I don't know anything but the most basic ones. Cisco tells me that I can't get support unless I purchase a support contract for $500, so I am hoping I can get some answers. I did find another board (experts-excahnge.com) that has given me some helpful hints.
Jeremy
|
|
|
|
Sponsored links
|
|
Advertisement
|
|
03-15-2003, 12:41 PM
|
#9
|
|
Low Bitrate
Join Date: Jan 2002
Location: UK
Posts: 87
|
We use pix at work and for the ISP we own. Have done a bit of pix work mainly via the web browser setup. Have you tried accessing the web browser setup??
I'll help anyway I can.
__________________
Car: About to change
Player: VIA Eden, 256Mb RAM, Bootable from 64MB Compactflash, 40GB MP3 HD, IRMan, Wireless Keyboard, 5.6" In-dash TFT, 12v DC-DC, running Windows XP Embedded with Wireless LAN, Mobile Internet, GPS Sat Navigation.
== Running MediaEngine for the front end whilst I build a front end in VB.NET, but may stick with ME 2.0 ==
|
|
|
03-15-2003, 03:19 PM
|
#10
|
|
Registered User
Join Date: Apr 2002
Location: South Coast, UK
Posts: 437
|
On ours the web filtering running on the Pix is a third party module, which is configured using a Windows client PC sitting in the DMZ. Maybe you have something similar?
__________________
-------------------------------------------
(=========-) 99% complete
--------------------------------------------
AMD K6/2 500 @ 450mhz to keep heat and power usage down, 64Mb, slim CDrom drive, 64mb USB pendrive for MP3 transfer, 10Gb 2.5" drive for MP3, USB>RS232
All jammed in external CDROM drive case.
Kenwood KVC-1000r In-Dash LCD. x-10 MouseRemote. Destinator V2 Gps. DC-DC with onboard Shutdown controller.
----------------------------------------------
|
|
|
|
Sponsored links
|
|
Advertisement
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 10:41 PM.
| |