PIX and ISA server integratio and internal servers with 1 public IP

Unanswered Question
Apr 29th, 2007
User Badges:

Dear All,

I want to integrate the ISA server to the pix firewall.

The pix firewall inside directly connected to the

ISA server outside inetrface (ISA-, Pix inside

There are 5 servers in the inside ISA server network ( 80,443 801, 25 80 3101

PIX config as below

nat (inside) 1 # only ISA outside goes for internet and client use

the ISA as proxy to access the internet

global (outside) 1 interface

int eth0

ip add

no sh

int eth1

ip add

no sh

static (inside,outside) netmask

accesss-list 101 permit ip any host

access-group 101 in interface outside

After the config the internet access in stoped.

If i check the show xlate it shows translated to

not the global cmd ip So the internet is stoped.

how can i configured both inbound and outbound thro the PIX as per the above design.

Ur reply is appreciated.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Rodrigo Gurriti Sun, 04/29/2007 - 13:43
User Badges:

I recommend you do:

1 NAT to inside hosts

2 Static NAT if you have a block of IP's or do a Static PAT if you only have one IP

3 Open the servers for the NAT with an access-list just like you tried to do on the ex above

then clear the xlate to make it affective


nat (inside) 1

static (inside,outside) netmask

????? why you did that ?

nat (inside) 1

global (outside) 1 interface

then you configure the statics

static (inside,outside) tcp interface ftp ftp netmask

static (inside,outside) tcp interface ssh ssh netmask

( I used the ftp and ssh as example you change to whatever you need )

now you need an access list to open the static servers

access-list OUTSIDE_TO_INSIDE remark Access-list for static allow trafic

access-list OUTSIDE_TO_INSIDE extended permit tcp any interface outside eq ssh

access-list OUTSIDE_TO_INSIDE extended permit tcp any interface outside eq ftp

then apply it

access-group OUTSIDE_TO_INSIDE in interface outside

arumugasamy Tue, 05/01/2007 - 23:30
User Badges:

Dear ,

Thanks lot.

Let me go the customer place to re-config again.

Also quick question.

I can ping the mpls switch ip add from of pix outside int.

If i change the pix outside ip to or any number i can not ping the switch .Tell me why since both in same subnet it has to reply for the changed IP also as it gives for the old one

I called the local ISP to check their switch (batelco provide and keep the switch config confident)they told that it will work even change the IP for the pix outside interface since it is directly connected to the switch MPLS



This Discussion