HI!
See my post about PIXCRIPT - it is designed for your kind of needs.
Here is a sample (fiction) configuration for you:
nameif ethernet0 outside security0
nameif ethernet1 inside security100
interface ethernet0 auto
interface ethernet1 auto
ip address outside 55.55.55.1 255.255.255.0
ip address inside 10.0.0.254 255.255.255.0
route outside 0.0.0.0 0.0.0.0 0.0.0.0
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) 55.55.55.2 10.0.0.2
access-list 101 permit tcp any host 55.55.55.2 eq smtp
access-group 101 in interface outside
Here is the same config for PIX ver 5.2 and older which does not support access-list commands:
nameif ethernet0 outside security0
nameif ethernet1 inside security100
interface ethernet0 auto
interface ethernet1 auto
ip address outside 55.55.55.1 255.255.255.0
ip address inside 10.0.0.254 255.255.255.0
route outside 0.0.0.0 0.0.0.0 0.0.0.0
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) 55.55.55.2 10.0.0.2
conduit permit tcp host 55.55.55.2 eq smtp any
Bye
Yizhar
Yizhar Hurwitz