ðòïåëôù 


  áòèé÷ 


Apache-Talk @lexa.ru 

Inet-Admins @info.east.ru 

Filmscanners @halftone.co.uk 

Security-alerts @yandex-team.ru 

nginx-ru @sysoev.ru 

  óôáôøé 


  ðåòóïîáìøîïå 


  ðòïçòáííù 



ðéûéôå
ðéóøíá












     áòèé÷ :: Inet-Admins
Inet-Admins mailing list archive (inet-admins@info.east.ru)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[inet-admins] Server farm with FW1 i Cisco NAT



Hi!

Zaatachil ASCII art, v kotorom narisovano to, kak vygladit shema seti. Na
Cisco hochetsa sdelatj NAT, shto-by dla Firewall-1 eto vygladelo kak odin IP
adres. Delajem NAT, ping idet, traceroute idet, a FTP, Telnet, NetBIOS, itd
ni v kakuju. V testovom rezhime na FW dla ServerFarm razresheno vse dla
vseh. Bez NATa - vse prohodit. V chem grabli? Mozhet NAT kak-to po umnomu
nuzhno delatj, osobenno, esli eto Ethernet-Ethernet NAT? 

Esli vkljuchit' "debug ip packet", to na Cisco E1 (na FW) vidni kakie-to
encapsulation errori... Nikakoi encapuljacii tam netu. IOSi v predelah 11.3
menjal - ne pomogaet. 12.x ne mogu postavit' ibo pamjati net.

Egons


           External networks
                   |
                   |
                   |
    S              |
    e f            |
    r a---------Firewall--------DMZ
    v r            |
    e m            |
    r              |  
                   |e1
                 Cisco
                   |e0
                   |  
                   |
                   |
                  LAN


 




Copyright © Lexa Software, 1996-2009.