02-29-2008 01:00 AM - edited 03-11-2019 05:10 AM
Hello,
I'm using Cisco Pix 515E, 8.0(3).
I have two networks - inside and dmz. Inside has sec. level 100, dmz 50. To communicate hosts from inside to dmz I made
static (inside,dmz) 172.16.0.0 172.16.0.0 netmask 255.255.0.0 tcp 0 10.
I think that Pix during NAT vindicate NAT-ed IP address on destination interface, so I had on these segments two devices with the same IP address.
Is it true? What is the best solution; disable nat-control and then disable static record?
Many thanks,
Vladislav
02-29-2008 07:45 AM
I am not sure what you mean by "I think that Pix during NAT vindicate NAT-ed IP address on destination interface, "
this is self static rule that you have in place...it will make sure the source is always preserved when you go from inside to dmz.
03-01-2008 03:51 AM
Hello,
I mean, when embryonic connection threshold is reached, pix acts as proxy and respond with syn-ack.
So when I make static identity NAT, I'm not sure if I will have two same IP address. One - the physical server, two - from which pix respond(after treshold). Becasue I make NAT, where inside IP addresses present on dmz side.
Vladislav
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide