Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

NAT behind a subnet

i have a network as attached.

i am translating to one single public address on the NAT router. this works fine. But, i am now adding a PIX firewall behind the router. and my servers is now on the subnet.

How do i make NAT working under this case? i am having trouble to do just a static NAT on the server since it is not direct connect to the router; and i am using the router to perform NAT.

  • VPN
New Member

Re: NAT behind a subnet

attach as shown

Hall of Fame Super Blue

Re: NAT behind a subnet


If you still want to do the NAT on the router you need to do a nat exemption for the server traffic on the pix.

Easiest thing to do would be

static (inside,outside) netmask


nat (inside) 0

This will mean all packets from 192.168.2.x servers will be left unnatted till they get to you router.

You will obviously need to update your NAT statements on the router to reflect the change in subnet from 192.168.1.x to 192.168.2.x.

If you don't want to NAT any traffic from inside your pix for any subnet you could just do

nat (inside) 0



Re: NAT behind a subnet

Is it possible to ask your ISP for some additionals ip addresses?

This widget could not be displayed.