Chaning T1 Service in PIX 525

Unanswered Question
Aug 20th, 2007

We are changing our T1 server to an other company; I know I need to change the IP address to the new provider on the outside, do I need to change the translation table and all ACL?s assoc with the old IP address. It would greatly appreciate if someone can put together some steps to follow or point me to a good document. Thanks

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
srue Mon, 08/20/2007 - 10:08

You need to change anything that references the old IP addresses, including but not limited to: NAT entries, ACL's, access management, DNS entries, VPN clients/peers, and anything else that might rely on the old addresses.

JORGE RODRIGUEZ Mon, 08/20/2007 - 11:11

Hi,

The previous poester spelled it out for you accurately, you need to make a thorought assesment of your current outside public IP block and create a change cutover plan that not only covers what Srue indicated but also default routes and one-to-one nat statements.

Start with ducumenting current static NATs related to public IP and internal mappings, global nat pools for outside interface etc.., from past experiences I have found that you mostly need to change logical IP addresses for one-to-one nats

and global pools, pay attention to your current local DNS services and current ISP and the new ISP.

If you have any other concerns or need assistance please drop us a line.

HTH

Jorge

jlwomeld Tue, 08/21/2007 - 04:24

Hi

After I follow all steps to change address, do I do the xlate on the FW and how long will this take to re-populate?

JORGE RODRIGUEZ Tue, 08/21/2007 - 12:00

Jerrie,

once you chnange static nat mappings you need to clear xlate , the clearing of xlate is immediate, once the new nat is configured with new IP info the change is also immediate.

e.g

say you chnage a static translations from old public IP to new public IP for a local host.

Old public IP: 10..10.10.1

new public IP: 20.20.20.1

local host IP: 30.30.30.1

no static (inside,outside) 10.10.10.1 30.30.30.1

clear xlate interface outside global 10.10.10.1 netmask 255.255.255.255

static (inside,outside) 20.20.20.1 30.30.30.1 netmask 255.255.255.255

Actions

This Discussion