Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Webcast-Catalyst9k
New Member

[836] map all IP ports to "default server"

Hi i have this situation

<INTERNET><836><PIX>

Cisco 836

outside ATM IP from ISP

Inside 10.0.0.1

routes to

10.0.1.0 255.255.255.0 > 10.0.0.2

10.103.0.0 255.255.0.0 > 10.0.0.2

PIX

outside 10.0.0.2

inside 10.0.1.1

the 836 is doing NAT for the network because i have 1 public ip. So far everything works,

but behind the pix a have 1 exchange server and 1 webserver, This is no problem, but i need to forward those smtp and http, https ports on the 836.

Now i thought can i forward all ip ports(tcp, udp, icmp) or set kind of "default server" to the outside of the pix so that i can work only on the pix which is better for administering the pix and i have no double settings.

Which setting does i need for the 836 to do this,

The LAN is configured and is working i wan't to have minimal changes because the firewalls are done.

1 REPLY
Silver

Re: [836] map all IP ports to "default server"

I would suggest that you decide on the list of protocols that you want to allow inside the network and then apply a filter to allow only those protocols. Allowing all ip ports is not a good idea. hope this helps

149
Views
0
Helpful
1
Replies
CreatePlease to create content