On a PIX 525, v6.3, I'm trying to create a static, and can't seem to get it to work.
My static command is:
static (dmz1,outside) 22.214.171.124 126.96.36.199 netmask 255.255.255.255 0 500
When I try to ping it, logg shows:
106014: Deny inbound icmp src outside:188.8.131.52 dst dmz1:184.108.40.206 (type 8, code 0)
When I try http://220.127.116.11, logg shows:
106001: Inbound TCP connection denied from 18.104.22.168/45593 to 22.214.171.124/80 flags SYN on interface outside
This PIX has no other statics. Another PIX I take care of has many statics - I have compared everything I can think of to compare between the two, but so far I can't find what I'm doing wrong.
One more piece of info: response to "sh xlate state static" varies. Sometimes the response includes 126.96.36.199, sometimes not. Attempts to ping and http produce the results above regardless of whether or not the address appears in the xlate table.
"System Messages" doc for v6.3 says "This message occurs when an attempt to connect to an inside address is denied by your security policy." But I don't see anything in the box's config that qualifies...
Any help will be most welcome...
Could you post the config of the pix as the static entry looks fine so there might be something else in your config.
Have you checked your acl's.