Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Troublesome PIX Config issue - Server cant access

Below is a config that appears almost line per line similar to a working config (I removed SNMP, Telnet etc..). The first PIX runs just perfectly.

The second which was being setting up this work has a few issues. First and foremost is the server at (mapped to 55.xx.xx.202) has no outgoing or incoming traffic. I can ping the PIX and vice versa, but can not access anything on the internet. Now all other devices could pull up remote sites without issue via http.

The second issue, which may be related is just as troublesome. To test out whether I could access the webserver from the outside, I connected to a remote office via VNC web/java interface. Problem was once the java app began to load it would just hang. Several times I swapped out the PIX and used the old firewall and could connect to remote devices without issue.

Now on the first PIX that we have had running for a long time, none of these issues exist.

Also I should add. In the internal network I have another webserver at In a previous config I had that mapped to external 55.xx.xx.205 with an access to HTTP. From the outside there was no issue connecting to this webserver.

Lastly, this troublesome server at, well when I changed the IP address to I had no trouble with connecting out to the internet. What in the PIX could specifically block a said IP address? The only listing was for the static mapping.

Any help or ideas will be greatly appriciated!

Here is the basic config, although the config has changed since I last worked on the device, having just erased the entire config, overall this is pretty much the same as before


PIX Version 6.3(5)

interface ethernet0 auto

interface ethernet1 auto

nameif ethernet0 outside security0

nameif ethernet1 inside security100


access-list outside_access_in permit tcp any host 55.xx.xx.202 eq www

pager lines 24

icmp permit inside

mtu outside 1500

mtu inside 1500

ip address outside 55.xx.xx.204

ip address inside

ip audit info action alarm

ip audit attack action alarm

pdm location inside

pdm history enable

arp timeout 14400

global (outside) 1 55.xx.xx.203

nat (inside) 1 0 0

static (inside,outside) 55.xx.xx.202 netmask 0 0

static (inside,outside) 55.xx.xx.205 netmask 0 0

static (inside,outside) 55.xx.xx.206 netmask 0 0

static (inside,outside) 55.xx.xx.207 netmask 0 0

access-group outside_access_in in interface outside

route outside 55.xx.xx.201 1


Re: Troublesome PIX Config issue - Server cant access

The address 55.xx.xx.207 is out of the usable range ! = Tot 8 address - 2 = 6 (BCST and NET)

Usuable IPs: 55.xx.xx.201 - 55.xx.xx.206

Network = 55.xx.xx.200

Broadcast = 55.xx.xx.207

Remove this static with:

no static (inside,outside) 55.xx.xx.207 netmask 0 0

Then do a clear xlate and then it should rock.

clear xlate