Workstation connecting to NAT address on the same subnet

Unanswered Question
Dec 17th, 2007
User Badges:

I was configuring a workstation in the DMZ to FTP to a host on the inside of the firewall. The workstation is on the same subnet as the NAT address of the host. When attempting to FTP to the NAT host, I never see the FTP connection attempt in the syslog. My question is. If the workstation and the NAT addresses are in the same subnet will the PIX forward the request on the host or ignore the request. If I attempt to FTP to the real address of the host, the connection is successful.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
husycisco Tue, 12/18/2007 - 05:40
User Badges:
  • Gold, 750 points or more

Hi Robert

Please explain "If the workstation and the NAT addresses are in the same subnet". With examples including IPs if possible


Regards


redavies5 Tue, 12/18/2007 - 06:53
User Badges:

access-list outside_access_in permit tcp host 192.168.1.81 host 192.168.1.78 eq ftp


The workstation (192.168.1.181) is in the DMZ (outside)and the host (192.168.1.178) is on the inside of the Firewall with a NAT.

husycisco Tue, 12/18/2007 - 05:50
User Badges:
  • Gold, 750 points or more

Duplicate post edited

Actions

This Discussion