Chaning T1 Service in PIX 525

Unanswered Question
Aug 20th, 2007
User Badges:

We are changing our T1 server to an other company; I know I need to change the IP address to the new provider on the outside, do I need to change the translation table and all ACL?s assoc with the old IP address. It would greatly appreciate if someone can put together some steps to follow or point me to a good document. Thanks

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
srue Mon, 08/20/2007 - 10:08
User Badges:
  • Blue, 1500 points or more

You need to change anything that references the old IP addresses, including but not limited to: NAT entries, ACL's, access management, DNS entries, VPN clients/peers, and anything else that might rely on the old addresses.

JORGE RODRIGUEZ Mon, 08/20/2007 - 11:11
User Badges:
  • Green, 3000 points or more


The previous poester spelled it out for you accurately, you need to make a thorought assesment of your current outside public IP block and create a change cutover plan that not only covers what Srue indicated but also default routes and one-to-one nat statements.

Start with ducumenting current static NATs related to public IP and internal mappings, global nat pools for outside interface etc.., from past experiences I have found that you mostly need to change logical IP addresses for one-to-one nats

and global pools, pay attention to your current local DNS services and current ISP and the new ISP.

If you have any other concerns or need assistance please drop us a line.



jlwomeld Tue, 08/21/2007 - 04:24
User Badges:


After I follow all steps to change address, do I do the xlate on the FW and how long will this take to re-populate?

JORGE RODRIGUEZ Tue, 08/21/2007 - 12:00
User Badges:
  • Green, 3000 points or more


once you chnange static nat mappings you need to clear xlate , the clearing of xlate is immediate, once the new nat is configured with new IP info the change is also immediate.


say you chnage a static translations from old public IP to new public IP for a local host.

Old public IP: 10..10.10.1

new public IP:

local host IP:

no static (inside,outside)

clear xlate interface outside global netmask

static (inside,outside) netmask


This Discussion