cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
220
Views
0
Helpful
4
Replies

PAT with PIX

admin_2
Level 3
Level 3

Hi,

Currently we have a small DMZ running it's own IP range and the addresses are running out. To overcome this problem we are moving to using PAT with the outside interface IP. The end goal is to provide services spread out over three servers in the DMZ by using 1 IP address.

I have started with the port for mail but I cannot get it to work.

The book tells me to add the following line

static (inside,outside) tcp ip_outside 25 ip_dmz 25 netmask 255.255.255.255 0 0

When I add this line using the CLI it shows up the GUI. But a connection to the ip_outside:25 gives me nothing.

No luck even when I make a rule allowing traffic to the ip_dmz:25 from ANY OUTSIDE source.

What am I missing?

4 Replies 4

mostiguy
Level 6
Level 6

you still need to open the port in the access list bound to the outside interface,

Not applicable

Thanks for the answer. So you saying that besides the static mapping you need to create a rule allowing traffic from ANY OUTSIDE source to the IP ADDRESS of the server. I cannot make a rule allowing ANY SOURCE on the outside to the IP address of the OUTSIDE interface, but I can to the IP of the server in the DMZ. But no luck yet. I will try again and let you know.

you need to allow from any to the port of the service on the ip that you are using.

Not applicable

I am using the IP address of the external interface of the PIX to connect to from the Internet. A rule allowing ANY from OUTSIDE to the IP of the OUTSIDE interface for this port is not allowed. When creating a rule allowing traffic from ANY source on the Internet to the IP I am using on the DMZ, a 10.5.x.x address. This rule still does not give me a connection.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card