I have a PIX 515e with 3 interfaces,
Inside (sec100) 10.0.10.1
DMZ (sec50) 10.0.20.4
Outside (sec0) 22.214.171.124
I have a server on the DMZ with RDP enabled, and from that server I can ping outside IPs by number, but not name. I can ping the server itself from outside and inside fine as well. The server IP is 10.0.20.10
I know I have an ACL problem but I am afraid of opening up certain ports for fear of defeating the DMZ's purpose altogether. So I ask you all what I need to do :)
I am attaching my config.
please let me know what I need to do to get to enable my servers on the DMZ to query the DNS servers on the inside network, also please let me know what I need to do to get Active directory logons working..currently when I try to logon to the server on the DMZ, it tells me that the System cannot log you on because the domain is not available. I assume port 389 needed to be opened on the DMZ ACL but there may be others as well.
If oyu see any other problems let me know. I will be moving all of the servers on this config to the DMZ once I get everything working properly.