Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Can PIX allow inbound connection with same Network as inside

I have a situation with an office attached to our internal network via a T/3 and sharing the same internal IP address space. Both offices have different ISP's. I also have a test web server on our internal network and it is being static assigned an external IP address from our pool at office A. The problem I am having is with office B trying to get to that external IP address from their ISP. Is the firewall blocking this?

New Member

Re: Can PIX allow inbound connection with same Network as inside

You’ll have to look at the PIX logs to see if the packet is arriving at the outside interface of the pix. The easiest way to do this is to turn on debug icmp and ping the static IP address from the remote site. If you see icmp packets on the debug, dig further into the debugging syslog files to see what is being denied. I assume you’ve setup a conduit allowing these packets in. If the source IP address on the remote site is the same network as the inside network, your host inside will assume the packet came from one of the hosts on it’s own wire and will never use the gateway (PIX) to return the packet to the remote site. Consider using rfc1918 reserved network addresses internally.