Re: Connecting 2 networks via Win 2003 server

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I am not sure exactly what it means! There is certainly something funny
happening on the PIX. I am not familiar with that firewall, so I can't
really say what the problem is. But the problem is there, not at the RRAS
router.

Mart wrote:
> On Fri, 13 May 2005 10:34:36 +1000, "Bill Grant"
> <not.available@online> wrote:
>
> If I place a static route on the PC1, I am able to ping PC1 from PC2.
> However I am unable to ping PC2 from PC1. I'm getting very confused!
>
> The fact that this does not happen when I do not have the static route
> on the PC, but in the firewall, does this mean that ICMP redirect
> packets are not being allowed through?
>
>
>> It shouldn't really matter. When a client in 192.168.254 tries to
>> access a target machine in 192.168.253 , the packet will go to its
>> default router (the PIX at 192.168.254.252) . The PIX will redirect
>> the packet to 192.168.254.250 (the RRAS router) because of the
>> static route you added. After this, it should send an ICMP redirect
>> to the sender to inform it of the correct address to use in future.
>> But the packet should have already gone.
>>
>> What happens if you put the static route directly on the client?
>> That should bypass the PIX altogether. The client should send the
>> packet to the RRAS router itself.


.



Relevant Pages

  • RE: [fw-wiz] Cisco PiX 501 running 6.2 - Defying me for no reason
    ... >>connected with the PiX between it). ... > assign static IPs, so when I transfered the static to the firewall, the ... I cannot ping names, such as ... server and have it issue an IP and DNS server to your client PC? ...
    (Firewall-Wizards)
  • Re: Cisco PIX 515 Firewall
    ... Subject: Cisco PIX 515 Firewall ... In regards to its packet inspection / logging... ... The PIX also intercepts and monitors SMTP, ...
    (Security-Basics)
  • Re: [fw-wiz] Help
    ... block any DNS packet larger than 512 by default. ... packet larger than 512 the firewall will drop the packet. ... The PIX can be configured to allow larger DNS ... If you could tell me the OS you used to dig, the firewall between your ...
    (Firewall-Wizards)
  • Re: Wait event "SQL*Net more data to client" in wait class "Network"
    ... connection on 10 hang for about 10 secondes. ... Is it a stateful firewall? ... the client and server (I have not had a chance to test Wireshark on 64 ... I'll try packet capture with my networking consultant. ...
    (comp.databases.oracle.server)
  • Re: Cisco Pix vs Watchguard Firebox
    ... >> A client of mine is looking for a new firewall in his office of around ... >> Watchguard. ... > the last 5 years and even replaced many PIX units. ...
    (comp.security.firewalls)