Check

if you have 
ip address inside ip address subnet mask
nat (inside)  0.0.0.0 0.0.0.0 0 0

and 
route outside 0.0.0.0 0.0.0.0 ip address 
route inside 0.0.0.0 0.0.0.0 ip address

this should work because inside is trusted.

--- David Bader <[EMAIL PROTECTED]> wrote:
> Hi Sam
> 
> did you do set your security-levels correctly ? the
> outside interface has to
> have the lowest security level and it would only be
> possible to build a
> connection initiated from a higher to a lower
> security level.
> 
> 
> 
> dave
> 
> 
> 
> -----Urspr�ngliche Nachricht-----
> Von: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]Im Auftrag von
> Sam
> Gesendet: Montag, 19. M�rz 2001 19:28
> An: [EMAIL PROTECTED]
> Betreff: PIX problem
> 
> 
> Hello Group,
> I am having trouble figuring out a small issue with
> a PIX firewall.  It is
> running ver 4.4(5).
> After entering the approriate static and conduit
> (WWW) commands, I tried
> accessing the host from our internal network using
> the external address and
> I was not able to.  I then tested from a machine
> that is outside our
> firewall and was able to access the host without any
> problem.
> 
> Is their a command that I am missing in order to let
> users on our internal
> network access hosts using the external IP
> addresses?
> Thanks in advance,
> Sam
> 
> 
> 
> _________________________________
> FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to
> [EMAIL PROTECTED]
> 
> _________________________________
> FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to
[EMAIL PROTECTED]


__________________________________________________
Do You Yahoo!?
Get email at your own domain with Yahoo! Mail. 
http://personal.mail.yahoo.com/

_________________________________
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

Reply via email to