Hi,
I have a PIX with the following Networks
Outside Inside DMZ
- I currently have a static NAT which allows an outside address direct access to the servers in the DMZ.
- There is a NAT which allows inside traffic to the dmz - keeping the source address.
I need to add a translation which allows servers in the DMZ access to hosts on the inside - keeping their original addresses.
I have created the access rule to allow the relevent ports from the DMZ to the inside. When I try to add a rule to translate DMZ to Inside, Dynamic, same address, it pops up warning me that the security rule that allows (2 - above) will be broken..
I get syslog errors saying "No translation group found for tcp src dmz dst inside...."
Any help anyone could offer would be great - even if it's only to tell me that I'm trying to do something that the pix can't do!
Cheers
Richard