Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Pix Alias command help needed. |
|---|---|
| Date: | Mon, 22 Nov 2004 17:13:12 -0000 |
I am assuming quite a lot so please let me know if I'm off the mark here. The link to the citrix server (the link being on a public server) points to a public address within your organisation? So a user outside the network would then traverse the firewall to get to the citrix server? A user inside the firewall would try to access the public address which is natted on the firewall to a private one inside. My suggestion (if the above is correct) is to use a named link on the web site. Get a public address assigned to the links and register this with an external DNS authority. The internally create a the same DNS domain and server record to the internal address. Ie Citrix.myorg.com -----> 81.123.43.23 (externally) Cirtix.myorg.com -----> 10.23.34.45 (internally) I think the pix is not allow internal users because it sees them trying to enter and exit the firewall on the same interface and there will be no nat rule to allow this. HTH Andy -----Original Message----- From: Chad Thomsen [mailto:mtbcyclist@yahoo.com] Sent: 18 November 2004 12:56 To: firewalls@securityfocus.com Subject: Pix Alias command help needed. I have a strange situtation and am trying to resolve it using the Pix Alias command although that may not be the correct way. I have users that access an exteranlly hosted company web site that is hosted by somebody else. They can go to the site and click an employee login link which takes them to an internal citrix server. Probablem is that since the server is inside the network the Pix is not letting the traffic though. People on the outside (traveling salesman or home users) can use the link, but users behind the firewall on the interanl network cannot. And yes I know this is not the most secure desgin so don't hammer me on that. If I can get approval I am going to create a login sever in the pix DMZ but the organziation I work for has a VERY tight IT budget. Any thought on how to resolve this? __________________________________ Do you Yahoo!? Meet the all-new My Yahoo! - Try it today! http://my.yahoo.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | cisco IOS firewall terminating pptp, Andrew Shore |
|---|---|
| Next by Date: | Re: DNS Best Practices Question, Dan Swanson |
| Previous by Thread: | Pix Alias command help needed., Chad Thomsen |
| Next by Thread: | FW-1 VPN's for SecuRemote and site to site connections, West, Matthew J |
| Indexes: | [Date] [Thread] [Top] [All Lists] |