cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
216
Views
0
Helpful
1
Replies

Question about PIX nat pools

spfister336
Level 2
Level 2

I've got a PIX 525 that has a pool of NAT addresses that looks like:

x.y.170.0 - x.y.175.253

x.y.175.254

Recently, a user had problems with Internet access and I noticed her address was mapped to x.y.174.255. Traceroutes went several hops to their destination and began timing out. Pings worked some places and some places not. I'm assuming some device along the line saw it as a directed broadcast and dropped it. Clearing the translation and allowing it to be assigned again worked and the user had normal access.

- Is my assumption about what happened correct?

- Is it possible to exclude the .255 addresses in that range, or do I need to delete it and put in 6 separate ranges?

- What will be the impact to existing sessions? Will they all be reestablished?

Thanks!

--Steve

1 Reply 1

John Blakley
VIP Alumni
VIP Alumni

- Is my assumption about what happened correct?

Possibly, but hard to say really.

- Is it possible to exclude the .255 addresses in that range, or do I need to delete it and put in 6 separate ranges?

I would recreate the pool and exclude your .0 and .255 addresses (x.x.170.1-x.x.170.254), and you would need to create 170 - 175 (so 6 pools).

- What will be the impact to existing sessions? Will they all be reestablished?

When you remove the global pools to create the separate split pools, the sessions will *probably* be torn down but will be reestablished. I would create downtime to do this. :-)

HTH,

John

HTH, John *** Please rate all useful posts ***
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card