Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Destination NAT on inside interface of Pix to DMZ host.

Hello experts.

I wonder if there is a solution to this problem. I have a single host in a dmz with a 515 pix at, and on internal interface. There is also an external I/F but it is irrelevant to the problem.

I want all users on my internal network to see this host at I want the Pix to Proxy arp for this address and NAT the destination to The Pix then delivers the traffic to the DMZ host. The host responds, and again the PIX NATs the response packet putting as the source ip of the response. I tried doing this with Static (dmz,inside) netmask 0 0

but it doesn't work because the PIX didn't appear to even proxy arp for the internal address. Nothing appears in log. So I added an ALIAS (inside)

Now it still doesn't work, but I get log entries when I try to ping the DMZ server from an Inside switch...

11-05-2006 12:24:08 Local4.Error May 11 2006 12:21:37: %PIX-3-305006: regular translation creation failed for icmp src inside: dst dmz: (type 8, code 0)

What can I do to make this type of NAT work for all protocols?


Re: Destination NAT on inside interface of Pix to DMZ host.

I think the alias can do the job but in your case it seems you configured the other way around.. it should say

ALIAS (inside)

I hope it helps ... please rate it if it does !!!