Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX 515 NAT Issue (or could be access list...)

Looked at this too many times, can't see what I'm missing...Incoming mail and web working fine, can't get anything out. Info loggin show lots of UDP DNS traffic do I need to open port 53 or something?...

nameif ethernet0 outside security0

nameif ethernet1 inside security100

nameif ethernet2 intf2 security10

access-list acl_in permit tcp any host X.X.X.171 eq www

access-list acl_in permit tcp any host X.X.X.171 eq smtp

interface ethernet0 10baset

interface ethernet1 100basetx

interface ethernet2 auto shutdown

ip address outside X.X.X.170

ip address inside W.W.W.1

ip address intf2

global (outside) 1 interface

nat (inside) 1 0 0

static (inside,outside) X.X.X.171 W.W.W.4 netmask 0 0

access-group acl_in in interface outside

route outside X.X.X.169 1

  • Other Security Subjects

Re: PIX 515 NAT Issue (or could be access list...)


could you try pinging You will no receive any reply packet (pix blocks) but you should check if '' is resolved to an IP address. If it is not resolved to an IP address, then there may be a problem with the configured DNS servers on the pc's and servers.

Instead of pinging, you could try nslookup (on a computer behind the pix) to see if you can reach your DNS servers.

Your config, as it is right now, should allow all outbound traffic.

Kind Regards,