Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Using statics for access

I know that the static statement is used to access a higher security level interface from a lower security interface. Also, if you want to disable NAT you use the formula static (high,low) high high. I have used the same formula with the static command in accessing my dmz from the inside (going from higher to lower). Although, in Pix software verison 6.2 it says you need to use nat and global commands to go from higher to lower. There is also an example of this in the following link - http://www.cisco.com/warp/public/110/mailserver_dmz.html. Anyway, are both ways OK to use? Or is one better/more secure than the other?

Thanks,

RJ

1 REPLY

Re: Using statics for access

Statics are for low to high and nat is used for high to low. You should follow this rule. Even is you disable NAT, you use static as it is still low going to high. Static from high to low isn't required as by default high has access to low (with nat command).

Hope it helps.

Steve

80
Views
4
Helpful
1
Replies