Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PAT/NAT Issue with Cisco PIX 515E

Hi there,

I have a PIX that is running 8.0.4 (is this the latest version as I can't find this anywhere on the Cisco website?) and have a problem with a PAT rule and hope someone can help.

I  have two external IPs that map to one internal IP and need to have different PAT rules in place.

These are the rules in question

static (inside,outside) tcp 8080 8080 netmask 
static (inside,outside) tcp range 10000 63535 range 10000 63535

The top rule works fine and any traffic coming from the internet works fine.  The lower rule is to NAT the external IP over a VPN link and it needs to do this for the high range of ports.  The command I have listed does not work but as you can see I want it to PAT everything over port 10000.

If anyone has any help they can offer with the problem that would be great.



Cisco Employee

Re: PAT/NAT Issue with Cisco PIX 515E

Are you sure this server when sourcing traffic will always source traffic between these ports 10000 63535?

I'd collect captures and make sure.

Most of the times, static pat is implemented for inbound flows.  You seem to be using this for outbound (high to low).

How about if you did

nat (inside) 5

global (outside) 5