Networking Forums

Networking Forums > Computer Networking > Linux Networking > PIX/Linux/ADSL2 Routing/NAT Issue.

Reply
Thread Tools Display Modes

PIX/Linux/ADSL2 Routing/NAT Issue.

 
 
Skymaster
Guest
Posts: n/a

 
      09-07-2006, 04:28 AM
Gday all....
got a few q's on how to properly implement & correct a routing problem
i have.
Consider the following physical network:


LAN --- (Switch) --- Linux --- (Switch) --- ADSL2+ Modem
+------ PIX -------+


Linux Int - 172.30.1.254, Ext- 172.30.250.254
PIX Int - 172.30.1.251, Ext- 172.30.250.251
ADSL - 172.30.250.250
ADSL External has static IP - 1.2.3.4

The LAN has the Linux box as its default gateway. This linux box is
NAT'ing this into the External Network, and the ADSL2 modem is NAT'ing
the external to the Internet.

The External interface of the PIX is defined as the 'DMZ' host in the
ADSL modem, so it receives all requests hitting the external interface.
This PIX then forwards on the requests to the appropriate LAN server
(mail + web etc). This PIX is also a PPTP/IPSEC Vpn server to allow
internet users to log into the LAN.

Now...why do it like this? I want the IPSec/Firewall features of the
PIX, but the PIX is a 10 user 501, which only has 10mbit interfaces,
and my ADSL2 connection is 24mbit, and I have around 30 machines on the
LAN.

Now, the problem. All the LAN users have no hassles accessing the
internet correctly. External services though...this is the issue. When
a user, for example, connects to port 25 for a SMTP session, hits the
1.2.3.4 address, the pix forwards it on to the correct server. When the
TCP stack on that server replies with its SYN/ACK though, it gets sent
back via the Linux machine, being the default route. This confuses the
ADSL modem, which treats it as a new packet, re-nat's it, and sends to
back to the user. The user's machine then replies with a RST because it
doesnt understand what the hell is going on. Hence the connection
fails. What to do?
I am puzzled. Any help would be fantastic - cheers!!

 
Reply With Quote
 
 
 
 
Walter Roberson
Guest
Posts: n/a

 
      09-07-2006, 06:00 AM
In article <(E-Mail Removed) .com>,
Skymaster <(E-Mail Removed)> wrote:
>Now...why do it like this? I want the IPSec/Firewall features of the
>PIX, but the PIX is a 10 user 501, which only has 10mbit interfaces,
>and my ADSL2 connection is 24mbit, and I have around 30 machines on the
>LAN.


FYI, The 10 Mbit outside interface restriction was removed in 6.3(1).
(But the 10 user license remained unchanged.)
 
Reply With Quote
 
Skymaster
Guest
Posts: n/a

 
      09-07-2006, 11:46 AM
Is there somewhere I can get a copy of this easily? Or would it involve
me handing over money to Cisco?


Walter Roberson wrote:
> In article <(E-Mail Removed) .com>,
> Skymaster <(E-Mail Removed)> wrote:
> >Now...why do it like this? I want the IPSec/Firewall features of the
> >PIX, but the PIX is a 10 user 501, which only has 10mbit interfaces,
> >and my ADSL2 connection is 24mbit, and I have around 30 machines on the
> >LAN.

>
> FYI, The 10 Mbit outside interface restriction was removed in 6.3(1).
> (But the 10 user license remained unchanged.)


 
Reply With Quote
 
Walter Roberson
Guest
Posts: n/a

 
      09-07-2006, 01:38 PM
In article <(E-Mail Removed). com>,
Skymaster <(E-Mail Removed)> wrote:
[PIX 6.3(1)]

>Is there somewhere I can get a copy of this easily? Or would it involve
>me handing over money to Cisco?


It depends on what your current version is. If you are in PIX 6.2 now
then you -might- be able to wrangle it through judicious use of
the PIX Security Advisories, but you'd need to look at them carefully
and be prepared to argue your case. (Security Advisories don't normally
allow you to upgrade.)
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ADSL2+ with BE Unlimited - Does ADSL2+ require 'training' adrian@awallis.demon.co.uk Broadband 3 03-02-2007 02:01 PM
Routing Issue Richard Edwards Windows Networking 4 05-15-2006 04:14 PM
3 NIC IP routing issue & local dhp client issue Grimmo' Windows Networking 6 05-04-2005 10:19 AM
Need Help With Routing Issue Will Windows Networking 1 04-21-2005 02:29 PM
linux routing issue Paul Linux Networking 0 10-25-2003 02:38 PM



1 2 3 4 5 6 7 8 9 10 11