Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

PIX Firewall - Accessing multiple internal networks

Hi everyone,

I have a PIX Firewall which I'd like to configure to allow IP addresses from the external interface (private IP range) to access multiple networks that exist on the internal network.

For example:

The internal network has a layer 3 switch with multiple vlans and I'd like to allow some IP addresses on the external lan access these internal networks. I've added the necessary 'route' commands on the pix and it can properly ping these internal networks/hosts. However, when trying to access them from the external network, I receive the 'no translation group found' error.

Assume the following setup:


Where 192.168.10.x is the internal network and 192.168.11.x the external.

I've also added:

route inside so that the pix can reach the network.

I need to access the network from the external network.

Many thanks for any input or suggestions.

New Member

Re: PIX Firewall - Accessing multiple internal networks

If you already permited 192.168.10.x with an ACL attached to outside interface then the only thing left to add is either a static no NAT statement or a policy based no NAT (Assume mask /24):

static (inside,outside) netmask

Or you can do:

access-list nonat extended permit ip

nat (inside) 0 access-list nonat

Either one of those will tell Pix to not translate the return traffic.

New Member

Re: PIX Firewall - Accessing multiple internal networks


I have already tried your suggestion and the debugging shows the original error I mentioned: "no translation group found" for

Again, this error occurs when 192.168.11.x (outside) tries to access 192.168.14.x which is an internal network that's not directly attached to the pix inside interface (the pix has an internal IP as a gateway in order to get to the 192.168.14.x network).

Perhaps a static (inside,outside) netmask would do the job ?

New Member

Re: PIX Firewall - Accessing multiple internal networks

Yes, if you are trying to reach on the inside then I would rewrite the static and give that a shot.

CreatePlease to create content