Tom's Hardware > Forum > General Networking > Firewall > PIX 515E and Symantec FW

PIX 515E and Symantec FW

Forum General Networking : Firewall - PIX 515E and Symantec FW

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: comp.security.firewalls (More info?)

 

Dear all,
we have installed a PIX 515 Ver. 6.3 behind our enterprise wide FW from
Symantec.
To explain our problem let' take this example:
We are allowing HTTP access only for hosts from our own company LAN.
Therefore any HTTP request from OUTSIDE is rejected as we can see it in
our log. That' fine BUT 2 or 3 minutes later the same request from the
same outside client is accepted because we see at the OUTSIDE interface
now the IP address of our Symantec FW which we trust.
Very strange!
Is there any explanation why this happens?

THX for your help!
Rainer B.

Sponsored Links
Register or log in to remove.

Archived from groups: comp.security.firewalls (More info?)

 

Rainer.Blaes@space.eads.net wrote:
> we have installed a PIX 515 Ver. 6.3 behind our enterprise wide FW from
> Symantec.

*ROTFL* - Sorry, but this is just _too_ funny *wipingtears*

> To explain our problem let' take this example:
> We are allowing HTTP access only for hosts from our own company LAN.
> Therefore any HTTP request from OUTSIDE is rejected as we can see it in
> our log. That' fine BUT 2 or 3 minutes later the same request from the
> same outside client is accepted because we see at the OUTSIDE interface
> now the IP address of our Symantec FW which we trust.
^^^^^^^^^^^^^^^^^^^^^^^^^^
> Very strange!

I marked your mistake.

Yours,
VB.
--
"Es kann nicht sein, dass die Frustrierten in Rom bestimmen, was in
deutschen Schlafzimmern passiert".
Harald Schmidt zum "Weltjugendtag"

Reply to Anonymous
Tom's Hardware > Forum > General Networking > Firewall > PIX 515E and Symantec FW
Go to:

There are 1358 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them