Configure static Port Address Translation (PAT) on the PIX.
Starting with PIX Software version 6.0, the PIX can be configured to translate ports destined to a single global IP address to multiple internal servers.
One place this would be useful is if you only have a single IP address available from your ISP, but your web server is on a different box than your mail server. You can use port redirection (static PAT) to accomplish this.
Address available from ISP: 22.214.171.124 Mail Server IP Address: 10.10.10.5 Web Server IP Address: 10.10.10.6
PIX commands are shown below.
static (inside,outside) tcp 126.96.36.199 25 10.10.10.5 25 netmask 255.255.255.255
static (inside,outside) tcp 188.8.131.52 80 10.10.10.6 80 netmask 255.255.255.255!--- Now that the port redirection is defined, we need
!--- to allow inbound access via an access list.access-list inbound permit tcp any host 184.108.40.206 eq 25
access-list inbound permit tcp any host 220.127.116.11 eq 80
access-group inbound in interface outside!--- Finally, if those two servers also need to initiate
!--- connections outbound, then we need to do PAT on
!--- them to the static address.nat (inside) 1 10.10.10.5 255.255.255.255
nat (inside) 1 10.10.10.6 255.255.255.255
global (outside) 1 18.104.22.168