So I am running Pix 515E on 6.3
I had a friend using some IP's that were pointed to one of my virtual machines, but I had him move them over to some other IP's since I needed to reclaim them.
The IP's he was using was
x.x.x.6
x.x.x.7
all entries from the firewall have been modified correctly, and x.x.x.7 now correctly points to the new server, but for some reason x.x.x.6 just does not forward correctly. It's like the server isn't there. If I point lets say x.x.x.99 to the server everything works fine, something funky is up with this x.x.x.6 IP.
I have a feeling something is maintaining some kind of open connection or something but the "show conn" doesn't list anything that I can see going to any of the old or new internal IP's.
Here are the relevant configs.
firewall# ping 10.128.1.32
10.128.1.32 response received -- 0ms
10.128.1.32 response received -- 0ms
10.128.1.32 response received -- 0ms
So the firewall sees the IP, but when trying to access the server from the outside I am not seeing anything. I've confirmed the server is working and I can get the web interface on the local server, and from other servers inside the LAN.
I had a friend using some IP's that were pointed to one of my virtual machines, but I had him move them over to some other IP's since I needed to reclaim them.
The IP's he was using was
x.x.x.6
x.x.x.7
all entries from the firewall have been modified correctly, and x.x.x.7 now correctly points to the new server, but for some reason x.x.x.6 just does not forward correctly. It's like the server isn't there. If I point lets say x.x.x.99 to the server everything works fine, something funky is up with this x.x.x.6 IP.
I have a feeling something is maintaining some kind of open connection or something but the "show conn" doesn't list anything that I can see going to any of the old or new internal IP's.
Here are the relevant configs.
object-group service rps tcp
port-object eq www
access-list acl_out permit tcp any host x.x.x.6 object-group rps
static (inside,outside) x.x.x.6 10.128.1.32 netmask 255.255.255.255 0 0
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
access-group acl_out in interface outside
firewall# ping 10.128.1.32
10.128.1.32 response received -- 0ms
10.128.1.32 response received -- 0ms
10.128.1.32 response received -- 0ms
So the firewall sees the IP, but when trying to access the server from the outside I am not seeing anything. I've confirmed the server is working and I can get the web interface on the local server, and from other servers inside the LAN.