10-24-2008 12:59 AM - edited 03-11-2019 07:02 AM
Hi, it is the first time I use a PIX, and I am having problems with NAT.
I have a serveur with an Internal Ip address 192.168.230.13
at the outside and ip addres is use 10.5.5.3
So I did a translation rule to a static IP,from 10.5.5.3 on outside to inside serveur 192.168.230.13.
then I tried to add a translation rule tha would use the same destination:
translation rule static with port address translation from 10.5.5.4:8080 on outside to 192.168.230.13:8080 on inside.
The firewall tells me that the second rule overlaps the firstone. this causes no problems in other firewall.
How can I do this properly on a Pix?
Thanks
10-24-2008 03:29 AM
Hi,
The solution is the policy nat where you can define exactly what traffic should be translated and how.
Take a look to this link:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800b6e1a.shtml
Hope it helps, rate if does,
Thanks,
Krisztian
10-27-2008 07:28 AM
After reading the document I was recomended, I did the following configuration:
interface gb-ethernet1 vlan229 logical
nameif vlan229 local security95
ip address local 192.168.229.254 255.255.255.0
name 192.168.229.2 lenovo
access-list outside_access_in permit tcp any host 212.44.229.2 eq ssh
access-list outside_access_in permit tcp any host 212.44.229.2 eq www
access-list outside_access_in permit tcp any host 212.44.229.2 eq smtp
ip address local 192.168.229.254 255.255.255.0
pdm location 212.44.229.2 255.255.255.255 outside
pdm location 212.44.229.3 255.255.255.255 outside
pdm location 212.44.229.4 255.255.255.255 outside
pdm location lenovo 255.255.255.255 local
pdm location 192.168.229.0 255.255.255.255 local
global (outside) 2 interface
nat (inside) 2 0.0.0.0 0.0.0.0 0 0
nat (local) 2 192.168.229.0 255.255.255.0 0 0
static (outside,local) tcp lenovo ssh 212.44.229.2 ssh netmask 255.255.255.255 0 0
static (outside,local) tcp lenovo www 212.44.229.3 www netmask 255.255.255.255 0 0
static (outside,local) tcp lenovo smtp 212.44.229.4 smtp netmask 255.255.255.255 0 0
static (local,outside) 212.44.229.2 lenovo netmask 255.255.255.255 0 0
but only the ssh conexions over 212.44.229.2 are routed to 192.168.229.2
the rest does not work.
Any idea??
10-27-2008 08:44 AM
Hi mate,
Can you please tell us exactly what your business requirements are so that i can help you?
Thanks,
10-27-2008 08:49 AM
Hi,
I think it is not complicated
Having used iptables and sofware firewall (like astaro) in the past , now I 'am tring to understand nat on a pix 6.3
I'm tring to redirect conexions to ports on externals ip addresses to a server with an internal ip I mean:
the connexion to 212.44.229.2:ssh most be redirected to 192.168.229.2:ssh ip
the connexion to 212.44.229.3:80 most be redirected to 192.168.229.2:80 ip
the connexion to 212.44.229.4:25 most be redirected to 192.168.229.2:25 ip
this is the config I am tring to set up but I am a little lost here.
thanks
10-28-2008 03:10 AM
Hi,
The order of your static statement is not correct I guess so first remove all the static statements and after add these:
static (local,outside) tcp 212.44.229.2 ssh lenovo ssh
static (local,outside) tcp 212.44.229.3 http lenovo http
static (local,outside) tcp 212.44.229.4 25 lenovo 25
Hope it helps, rate if does
Krisztian
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: