cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
389
Views
0
Helpful
2
Replies

VPN client connected but I cannot access or ping to DMZ servers

arthur.phan
Level 1
Level 1

I am just having a problem with VPN Client 4.x, after the client connected (from a Windows 2000/SP4 or Windows XP/SP2 workstation), I could ping and access to the internal servers ok, but not the DMZ servers anymore. No configurations were changed from the PIX or Concentrator 3015.

Many THANKS for your help.

aphan

2 Replies 2

b.speltz
Level 4
Level 4

If internal clients need to access servers off of the DMZ interface of the PIX, and their DNS server is located on the PIX outside interface, then the PIX must do Destination Network Address Translation (DNAT) to the packets from the inside interface to the DMZ.

Here are two possible solutions:

If the PIX runs version 6.2 or later, issue this command:

static (dmz,inside) translated_IP real_ip dns

For PIX software versions 6.1 and earlier, the alternative is to issue the alias command.

alias (inside) translated_IP real_IP

I have decided to reboot the Concentrator and it is now functioning back to normal.

Many thanks for your reply and I will keep your solutions just in case I may need it in the future...

Regards.