"Jonathan Schwartz" <(E-Mail Removed)> wrote in message
news:eban-(E-Mail Removed)...
> The topology is: Netopia router to PIX 515 fierwall configured with a
> DMZ to which one of the RRAS server NICs is attached. Also, there is a
> NIC attached to the local LAN switch and NIC direct attached to a NAS
> box.
So there are two firewalls there. The Netopia is a NAT device,...making it
technically a "firewall",...they are not "routers",..calling them routers
was a bad marketing decision by the SOHO marketing departments of the world.
You should get rid of it,..leave the "modem" if this is a CableTV or DSL
connection and plug the PIX directly into the modem the way the Netopia was.
By simplfying the topology and getting rid of needless devices, will make
troubleshooting easier.
Why is the RRAS box on the Tri-homed DMZ? When the Users connect to it they
become part of the DMZ segment,...wouldn't you want them to become part of
the LAN instead?
--
Phillip Windell
www.wandtv.com
The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------