Networking Forums

Networking Forums > Computer Networking > Windows Networking > Route Back in - Windows 2003 DNS and Pix Firewall

Reply
Thread Tools Display Modes

Route Back in - Windows 2003 DNS and Pix Firewall

 
 
Jordan Turner
Guest
Posts: n/a

 
      09-29-2005, 08:24 PM
PIX Firewall with Windows 2003 DNS

We have a web server that can be accessed at WEB.DOMAIN.COM internally. We
have an external DNS record for this at WEB.DOMAIN.ORG. Users from the
outside can access WEB.DOMAIN.ORG, but users internally can NOT go to
WEB.DOMAIN.ORG. Basically, it can't go public IP and then private IP from
internal users. For external users it can. I can create a new DNS Zone for
this .ORG address but that is too much manual work.

From DNS perpective, Stub Zone and Forward Zone will not currently work
because we can't loop back in. New Zone works because we are pointing to
internal only - but is too much manual work - 85+ static names and IPs to
maintain.

Is there something on the PIX firewall to enable this functionality of
allowing traffic to go out then come back in? What is this terminology?

Thanks.


 
Reply With Quote
 
 
 
 
Bill Grant
Guest
Posts: n/a

 
      09-29-2005, 11:22 PM
No, you can't do that. A NAT/PAT device will not route private traffic
out to the public side then back in again. What you have to do is arrange
your DNS so that the machines on the private LAN resolve the web site's name
to its private IP. It is a name resolution problem, not a routing problem.

Jordan Turner wrote:
> PIX Firewall with Windows 2003 DNS
>
> We have a web server that can be accessed at WEB.DOMAIN.COM
> internally. We have an external DNS record for this at
> WEB.DOMAIN.ORG. Users from the outside can access WEB.DOMAIN.ORG,
> but users internally can NOT go to WEB.DOMAIN.ORG. Basically, it
> can't go public IP and then private IP from internal users. For
> external users it can. I can create a new DNS Zone for this .ORG
> address but that is too much manual work.
> From DNS perpective, Stub Zone and Forward Zone will not currently
> work because we can't loop back in. New Zone works because we are
> pointing to internal only - but is too much manual work - 85+ static
> names and IPs to maintain.
>
> Is there something on the PIX firewall to enable this functionality of
> allowing traffic to go out then come back in? What is this
> terminology?
> Thanks.



 
Reply With Quote
 
Sam
Guest
Posts: n/a

 
      09-30-2005, 02:07 AM
Bill I thought so too, BUT I am doing that with another client. I just do
not know how that particular client's ISP handles that. I am certain that
there is a way to do it.

In summary, If a client has an external DNS name and address which points
back to an internal ip and host, there is a way for it go to the external
DNS and have it come back internally - public to private mapping.


"Bill Grant" <not.available@online> wrote in message
news:(E-Mail Removed)...
> No, you can't do that. A NAT/PAT device will not route private traffic
> out to the public side then back in again. What you have to do is arrange
> your DNS so that the machines on the private LAN resolve the web site's
> name to its private IP. It is a name resolution problem, not a routing
> problem.
>
> Jordan Turner wrote:
>> PIX Firewall with Windows 2003 DNS
>>
>> We have a web server that can be accessed at WEB.DOMAIN.COM
>> internally. We have an external DNS record for this at
>> WEB.DOMAIN.ORG. Users from the outside can access WEB.DOMAIN.ORG,
>> but users internally can NOT go to WEB.DOMAIN.ORG. Basically, it
>> can't go public IP and then private IP from internal users. For
>> external users it can. I can create a new DNS Zone for this .ORG
>> address but that is too much manual work.
>> From DNS perpective, Stub Zone and Forward Zone will not currently
>> work because we can't loop back in. New Zone works because we are
>> pointing to internal only - but is too much manual work - 85+ static
>> names and IPs to maintain.
>>
>> Is there something on the PIX firewall to enable this functionality of
>> allowing traffic to go out then come back in? What is this
>> terminology?
>> Thanks.

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Desiging Back-to-Back ISA Firewall & VLAN Routing Habibalby Windows Networking 1 01-02-2009 03:20 PM
Disable dynamic route entries in Windows 2003? MikeS@MLS Windows Networking 3 09-18-2008 04:14 PM
Route add help on Windows Server 2003 Aaron Humperdoomperdinker Windows Networking 2 04-06-2006 12:37 AM
FTP Timeout Issue on Windows 2003 SP1 with Windows Firewall Sean Stromberg Windows Networking 0 02-13-2006 07:27 PM
FTP PASV for Windows Server 2003 SP1 Windows Firewall Yoshihiro Kawabata Windows Networking 0 09-12-2005 06:08 PM



1 2 3 4 5 6 7 8 9 10 11