Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

Single Public IP Address to Multiple Private IP DMZ Hosts

Hi.

I know everyone has likely been over all the ways in which this can be achieved with the PIX, but is Port Redirection with multiple Statics the only way to achieve this?

Basically, we have only 1 external IP Address we can use, but I need it to host FTP, WWW and SMTP on 3 different physical servers / hosts in the DMZ, each with its own single private IP address. Literature talks at length about having to have a one-to-one IP NAT relationship for all hosted services from the DMZ to outside, but how can I get the PIX (515 - latest software), to allow access to each of these servers from a single public IP address?

Thanks for your guidence

6 REPLIES
Silver

Re: Single Public IP Address to Multiple Private IP DMZ Hosts

You cannot host 3 different physical servers, period. PIX is not a load balancer.

You could, via http host headers, host 3 different http (not https) web sites on one server. There is no solution for ftp or smtp. If you run your ftp or smtp on non standard ports, people will likely have trouble contacting them

New Member

Re: Single Public IP Address to Multiple Private IP DMZ Hosts

Sure - what I was really thinking of was hosting FTP on one server, HTTP on another and SMTP on a third (in the DMZ). However, all services would have to be accessible through a single public IP Address - can I tell the PIX to map one public external Internet address to three different services, each on a different machine in the DMZ?

Silver

Re: Single Public IP Address to Multiple Private IP DMZ Hosts

That should be completely doable with port forwarding via statics, so long as you are running a relatively modern PIX OS.

New Member

Re: Single Public IP Address to Multiple Private IP DMZ Hosts

Thanks - that's the message I get from others on the subject too. How was this achieved before in older versions of the Cisco PIX IOS? Conduits?

Gold

Re: Single Public IP Address to Multiple Private IP DMZ Hosts

Hi James,

Have a read of the following document:

http://www.cisco.com/warp/public/707/28.html

Thanks - Jay.

New Member

Re: Single Public IP Address to Multiple Private IP DMZ Hosts

Thanks for everyone's help. That's sorted the issue out completely now. Cheers.

264
Views
0
Helpful
6
Replies
CreatePlease to create content