I have a need for a single ip host to connect through the outside interface of a PIX (6.3) to any destination host on the inside network 172.16.0.0. There are dozens of 172.16.0.0 addresses they need to connect to, and I need to do some sort of no nat so they can translate to themselves. I cannot just nat the whole 172.16.0.0 network to itself, as it will break other static NAT statements for the 172.16.0.0 subnet that are in place. I only want this single outside host to be able to connect to any inside 172.16.0.0 address without having to define a static translation for every possible destination address. how do I set this up?
Just leave the static statement for net 172.16.0.0/16 to the bottom of all configured static on the pix. The pix processes the static statements from top to bottom. Be carefull with the outside ACL's not to leave access from anyone to 172.16.0.0.
Yep! but remember to keep this translate statement to the bottom of all existing static's defined on the pix. Also once in a while a bit of maintenance has to be done. If you add some more static into that range, the existing static 172.16.0.0/16 must be removed then re-added to the config to ensure a proper 'translating'. Also a clear xlate has to be done for newest hosts added.
You may verify proper translate configuration using command:
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...