VPN client connected but I cannot access or ping to DMZ servers
I am just having a problem with VPN Client 4.x, after the client connected (from a Windows 2000/SP4 or Windows XP/SP2 workstation), I could ping and access to the internal servers ok, but not the DMZ servers anymore. No configurations were changed from the PIX or Concentrator 3015.
Re: VPN client connected but I cannot access or ping to DMZ serv
If internal clients need to access servers off of the DMZ interface of the PIX, and their DNS server is located on the PIX outside interface, then the PIX must do Destination Network Address Translation (DNAT) to the packets from the inside interface to the DMZ.
Here are two possible solutions:
If the PIX runs version 6.2 or later, issue this command:
static (dmz,inside) translated_IP real_ip dns
For PIX software versions 6.1 and earlier, the alternative is to issue the alias command.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...