Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

Passing DCOM/COM through PIX

Has anyone had any success in passing DCOM/COM through a PIX or any other firewall for that matter. I have one host (Web Server) in a DMZ off the PIX and the other host (Middle Tier)is inside. I have tried NAT'ing the (MIddle Tier) out to the DMZ and letting FULL IP connectivity to it. I have also tried NAT'ing the (Middle Tier) to itself out in the DMZ. (Example, static(inside,web_dmz) ) I have seen this work sometimes when trying to NAT NetBios. From what I understand DCOM uses port 135/tcp,135/udp,137/tcp, and some high range ports. I have used Microsoft's utility called DCOMCNFG to narrow the ports down to 5500-5550. I see that the 2 hosts are using these ports, but connectivity and performance are extremly slow and not constant.


Re: Passing DCOM/COM through PIX

You’re probably going to have to put a sniffer on the wire to see what’s happening. If you are translating to the same address, it’s not a NAT issue. There may be a problem with multi-homed servers or the protocol stack setup in the MS server. Sniffing the packets will help you determine what’s going where and why.

Community Member

Re: Passing DCOM/COM through PIX

Check out this article. It may help.

CreatePlease to create content