Hi Everyone,
have a question, I have 3 different subnets from my isp. What I need to know is if the pix can handle the 3 different subnets or do I need a pix for each subnet. I want to disable nat, and have the machines using external address, with access-list permitting services.
example: subnet1: 192.168.1.1 -254
subnet2: 192.168.2.1-254
subnet3: 192.168.3.1-254
pix outside interface 192.168.5.1 255.255.255.0
pix inside interface 192.168.1.1 255.255.255.0
pix dmz1 192.168.2.1 255.255.255.0
pix dmz2 192.168.3.1 255.255.255.0
nat (inside) 0 192.168.1.0 255.255.255.0
nat (dmz1) 0 192.168.2.0 255.255.255.0
nat (dmz2) 0 192.168.3.0 255.255.255.0
static (inside) 192.168.1.2 192.168.1.2 netmask 255.255.255.255
static (dmz1) 192.168.2.2 192.168.2.2 netmask 255.255.255.255
etc...
plus access-list ....