Help me please as I have run into a wall and can't figure this out. I have a PIX 515-BUN-UR running ver 6.2 of the PIX Firewall IOS with a 4-port serial card and the 3DES accellerator board. I have the VPN up and running sucessfully but now need to add a web server on the DMZ-1 interface.
The PIX is located directly after the Telco Border Router and has been assigned the address range of 188.8.131.52/29. Router interface is 184.108.40.206, PIX is 220.127.116.11. NAT is set to 18.104.22.168 and PAT is set to 22.214.171.124. I want the WEB service on 126.96.36.199. 188.8.131.52 is used for the IDS box between the Firewall and the Border Router.
I have added the following lines to the Firewall Config to set up the http access, but am unable to get into the web server:
access-list VPN permit ip ODH 255.255.0.0 192.168.127.0 255.255.255.0
access-list WEB permit tcp any host 184.108.40.206 eq www
access-group WEB in interface outside
ip address outside 220.127.116.11 255.255.255.248
ip address inside 192.168.128.5 255.255.255.0
ip address DMZ-1 192.168.136.1 255.255.255.0
global (outside) 1 18.104.22.168
global (outside) 1 22.214.171.124
global (DMZ-1) 1 WebServer netmask 255.255.255.0
nat (inside) 0 access-list VPN
nat (inside) 1 ODH 255.255.0.0 0 64
nat (DMZ-1) 1 0.0.0.0 0.0.0.0 0 10
static (DMZ-1,outside) 126.96.36.199 WebServer netmask 255.255.255.255 0 10
route outside 0.0.0.0 0.0.0.0 188.8.131.52 1
route inside 192.168.127.0 255.255.255.0 192.168.128.2 1
route inside OSHQ 255.255.128.0 192.168.128.2 1
If it makes any difference, I am also unable to ping the host on the DMZ-1 interface from the PIX console. The Web Host can be ping'd from a switch console, however the PIX interface cannot.
Can anyone please point me in the right direction.
Thanks in advance.