11-23-2009 06:03 AM - edited 03-11-2019 09:41 AM
My ISP gives me 5 public IP addresses that are advertised through a router they provided. The router is plugged into a PIX506E firewall. Is there a way to configure more than one public IP on the firewalls "outside" interface?
Thank you!
J.
Solved! Go to Solution.
11-23-2009 06:41 AM
ph0enix wrote:
My ISP gives me 5 public IP addresses that are advertised through a router they provided. The router is plugged into a PIX506E firewall. Is there a way to configure more than one public IP on the firewalls "outside" interface?
Thank you!
J.
J
You don't have to. As long as the ISP routes these addresses to your pix (and they will be doing) then you can simply use these addresses in NAT statements. So lets say one of the public IPs is 195.17.17.10 and you want to present an internal server to the outside, the internal server being 192.168.5.10. And you want to allow http to this server.
static (inside,outside) 195.17.17.10 192.168.5.10
access-list outside_in permit tcp any host 195.17.17.10 eq 80
access-group outside_in in interface outside
then anybody on the outside of the pix can connect to 195.17.17.10 on port 80 and the pix will redirect it to 192.168.5.10
Jon
11-23-2009 06:41 AM
ph0enix wrote:
My ISP gives me 5 public IP addresses that are advertised through a router they provided. The router is plugged into a PIX506E firewall. Is there a way to configure more than one public IP on the firewalls "outside" interface?
Thank you!
J.
J
You don't have to. As long as the ISP routes these addresses to your pix (and they will be doing) then you can simply use these addresses in NAT statements. So lets say one of the public IPs is 195.17.17.10 and you want to present an internal server to the outside, the internal server being 192.168.5.10. And you want to allow http to this server.
static (inside,outside) 195.17.17.10 192.168.5.10
access-list outside_in permit tcp any host 195.17.17.10 eq 80
access-group outside_in in interface outside
then anybody on the outside of the pix can connect to 195.17.17.10 on port 80 and the pix will redirect it to 192.168.5.10
Jon
11-23-2009 06:49 AM
Thank you, Jon!!!
I found this post while awaiting a reply (I know, I should have looked harder before posting):
It says the same thing. It worked like a charm!
J.
11-23-2009 06:51 AM
No problem, glad to have helped.
Jon
11-23-2009 06:53 AM
I would like to rate you answer but I can't figure out how to do that. The old system had a rating drop down which I'm not seeing anymore.
11-23-2009 07:12 AM
No worries.
I think to rate you use the left hand stars in the message box at the bottom left. Takes a bit of getting used to this new site
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide