cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
741
Views
0
Helpful
1
Replies

PAT/NAT Issue with Cisco PIX 515E

cisco
Level 1
Level 1

Hi there,

I have a PIX that is running 8.0.4 (is this the latest version as I can't find this anywhere on the Cisco website?) and have a problem with a PAT rule and hope someone can help.

I  have two external IPs that map to one internal IP and need to have different PAT rules in place.

These are the rules in question

static (inside,outside) tcp 89.151.103.19 8080 192.168.10.36 8080 netmask 255.255.255.255 
static (inside,outside) tcp 89.151.103.9 range 10000 63535 192.168.10.36 range 10000 63535
netmask 255.255.255.255

The top rule works fine and any traffic coming from the internet works fine.  The lower rule is to NAT the external IP over a VPN link and it needs to do this for the high range of ports.  The command I have listed does not work but as you can see I want it to PAT everything over port 10000.

If anyone has any help they can offer with the problem that would be great.

Thanks

Tim

1 Reply 1

Kureli Sankar
Cisco Employee
Cisco Employee

Are you sure this server 192.168.10.36 when sourcing traffic will always source traffic between these ports 10000 63535?

I'd collect captures and make sure.

Most of the times, static pat is implemented for inbound flows.  You seem to be using this for outbound (high to low).

How about if you did

nat (inside) 5 192.168.10.36

global (outside) 5 89.151.103.9

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: