Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Pix 6.33 static dns command problem


Recently , I upgrade my pix 515-ur from 6.1 to 6.33

I feel something wrong

this is my static command , it works fine on ver 6.1

static(inside,outside) tcp domain domain dns netmask

static(inside,outside) tcp www

dns netmask

my dns server's real IP is

my web server's real IP is

When someone want access my web server , Pix will translate my Web server ( to public IP (

everything is oK on ver 6.1 (do not need Alias command)

But when I upgrade to pix 6.33 ,

the static can not translate DNS name from to, I will translate just, so outside user can not access my Web server

Why ??

I have key "clear xlate " serval times

  • Other Security Subjects
ovt Bronze

Re: Pix 6.33 static dns command problem


Hystorically there are many bugs in the "DNS doctoring" functionality on PIX. As a possible workaround disable "port redirection" in the static (use entire IP address for your www server, rather than just port 80). If it doesn't help try to reconfigure static the other way round: "static (outside, inside) dns". Also, check the DNS fixup: "fixup protocol dns". It should be turned on.


Oleg Tipisov,



New Member

Re: Pix 6.33 static dns command problem

I guess I have a similar problem with 6.2(3).

I'm configuring all our publicly accessible machines (for Web, Mail and DNS) on the DMZ, with static mappings to appropriate addresses on the inside and outside. Everything works except for DNS rewriting on the static mappings, which persists in offering the DMZ local addresses, rather than the corresponding inside or outside address.

I've tried reversing the static commands, and I have only the undocumented 'fixup protocol domain nn'.


New Member

Re: Pix 6.33 static dns command problem

To my delight, this was all working the following morning. 'clear xlate' was needed for the adding

of dns to the static definition to have immediate effect!

This widget could not be displayed.