I've got a web server in the DMZ (single IP address). I somehow managed to get the users from the inside interface to access the web server in the DMZ but sometimes its takes about 20 to 30 seconds to show up which is way too long. Is this to do with my DNS settings or with the PIX settings? Which of the two settings below should I use for the pix?
DMZ Subnet: 10.3.30.0 / 255.255.255.0
DMZ web server: 10.3.30.100
Inside Subnet: 172.16.0.0 / 255.255.0.0
static (inside,dmz) 172.16.0.0 172.16.0.0 netmask 255.255.0.0
acl dmz permit tcp 10.3.30.0 0.0.0.255 172.16.0.0 0.0.255.255 eq 80
access-group dmz in interface dmz
or no nat?
access-list nonat extended permit ip 172.16.0.0 255.255.0.0 10.3.30.0 255.255.255.0
nat (inside) 0 access-list nonat
Or should I create and ip pool?
If it's none of the above, could you please give me a suggestion of what to do (what config I should enter)?
Thanks. Appreciate it.