Pix and OSPF

Unanswered Question


I'm using a Pix firewall 525 with 7.1(16) software version. I configure the ospf protocol on outside interface, in order to communicate with my external router. The Pix does Nat and Pat, and i want to know how insert the NAt e PAT address in OSPF database ( ie, I enable the ospf on outside interface ( /29 subnet ) of Pix and I use a different set of subnets to perform Nat and pat. So, what is the way ( if it exist )to redistribute these subnets in the network by OSPF?

Thanks a lot for your help

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 3 (1 ratings)
sachinraja Thu, 02/22/2007 - 16:07

Hello Paolo,

If you are doing NAT with a different subnet , you would obviously add a route on the external router pointing to the outside interface of the PIX. right ? You can redistribute this static route on the outside router into the OSPF domain. It will be propogated to other routers, so any packet destined for the NAT IP will be routed through the external router's interface. this is the best way of doing this. if you want to do it on the ASA, try adding a network statement on the ospf process (/32 network statement) and see if it gets populated on the ospf database and gets propogated.

Hope this helps.. all the best.. rate replies if found useful..



This Discussion