Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

PIX 515 setup with 1 external IP

We currently have a /30 external subnet to the internet (2 IP address in reality, 1 on outside of PIX, 1 on perimeter router). We want to allow 4 inside machines outbound using a variety of protocols and SMTP traffic inbound to the mail server. One of the inside machines is an HTTP proxy. I was going to use PAT oubound and static PAT inbound. Is this the best way of doing this given the lack of IPs?

Will PATing a proxied HTTP request result in degraded performance?

1 REPLY
Silver

Re: PIX 515 setup with 1 external IP

You should be fine so long as the http proxy doesn't serve thousands of users. Theoretically, PAT can work for 65k connections, but in practice there are some limitations. Running out of PAT translation slots should be the only possible performance limitation, and that should only happen if you have 10s of thousands of concurrent connections.

95
Views
5
Helpful
1
Replies
CreatePlease to create content