Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PIX DMZ-Inside servers

I have a PIX 520, running 5.3(1) with the webserver in a DMZ and SQL server on the inside Interface. Everything was working fine until yesterday, no changes were made, but traffic trough the PIX was spotty at best. I can now access the Internet from the Inside and the DMZ, and I can access the web-server from the outside world. The problem I am running into is that the web server sends data back to the SQL server for on-line ordering, and that is currentl not working. I cannot ping from the inside to the DMZ, and the reverse is the same.

Cisco Employee

Re: PIX DMZ-Inside servers

If you're trying to ping from any interface to any interface, you need to open up a conduit/ACL for that, as the PIX doesn't allow ICMP messages thru by default (it doesn't create a connection for it since it's not UDP/TCP based).

For the SQL server problem, do you see any errors in the PIX syslogs when the SQL server tries to contact the web server? If you see any denies, then you haven't opened the right access thru the PIX to get it to work.

CreatePlease login to create content