Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Pix 515 with multiple interfaces seeing each others and Active DIrectory

I’ve configured a CISCO PIX 515 E- unrestricted IOS v. 6.1 with 6 interfaces for a Customer. We have hosts on Windows 2000 and NT platform spread in each subnet. I’ve implemented NAT to grant the higher security interfaces to talk with the lower and vice versa.

nameif ethernet0 outside 0

nameif ethernet1 inside 100

nameif ethernet2 ServerFarm 50

nameif ethernet4 DMZ_Pubblica 30

nameif ethernet5 DMZ2 80

ip address outside

ip address inside

ip address ServerFarm

ip address DMZ_Pubblica

ip address DMZ2

nat (inside) 1

nat (ServerFarm) 1

nat (DMZ_Pubblica) 1

nat (DMZ2) 1

global (outside) 1 netmask

global (ServerFarm) 1 netmask

global(DMZ_Pubblica) 1 netmask

global (DMZ2) 1 netmask

static (inside, DMZ_Pubblica) netmask

So when a host on DMZ_Pubblica needs to access a server, with IP address, in inside network, will have to open a session with

The Active Directory is in the subnet named ServerFarm. When the Active Directory Server receives a request coming from a host in DMZ_Pubblica, with IP address 172.16.48.yy, to resolve the name for a server in the network inside, with IP address 172.16.16.xx, the AD Server will have to answer the IP address natted 172.16.48.xx. When the AD Server receives a request from a host in DMZ2, with IP address 172.16.64.zz, for the same server in the network inside will have to give another IP address natted 172.16.64.xx and it’s impossible.

I can fix it with lmhosts files or I must modify each WINS server, but the customer would rather not do that on every machine and complains because he believes it takes too long to resolve names. Is there any other solutions?

May I not apply NAT mechanism between the interfaces?

Thanks in advance


VIP Purple

Re: Pix 515 with multiple interfaces seeing each others and Acti

I'd consider not using NAT between the internal interfaces.

However, there is another solution. Read up on the "alias" command. This tells the PIX to re-write the IP address returned in DNS queries on the fly.

CreatePlease to create content