Pix and vlan allowing traffic

Mar 22, 2006 2 Replies

Hello,



Is it possible to allow traffic from workstations located on vlan10 to fileserver (samba) located on vlan20? VLAN20 is on lower security interface.



Thank you.


In article , ntst wrote: [PIX 506E]

Yes. If you do not have an access-group applied to vlan10 then that traffic would be permitted by default. If you do have an access-group, then allow it in the named access-list .

Return traffic is also of concern. SMB can be over TCP or over NETBIOS (UDP). If you happen to be using the NETBIOS version

-and- if the server sends asynchronous packets to the clients or the server might delay a response for over 2 minutes [e.g., waiting until a file becomes unlocked] then the UDP session might time out. To deal with that you would have to either raise the UDP timeout or else permit the UDP traffic in an access-group applied to the vlan20 interface.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required