Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

NAT in a DMZ

Status
Not open for further replies.

nix45

MIS
Nov 21, 2002
478
US
I have the following setup...

Internet
|
|
1.2.3.4
PIX15
192.168.2.1
|
|
192.168.2.2
Cisco 2621 Router
192.168.1.1

I have a server behind the router with an IP address of 192.168.1.250. I want to NAT this server to a public IP of 1.2.3.5. Can I use this command on the PIX even though the server it not on the same subnet as the PIX...

static (inside,outside) 1.2.3.5 192.168.1.250 netmask 255.255.255.255 0 0

...or do I have to place the server in the DMZ?


Thanks,
Chris
 
Though it is much better to place the server in a DMZ (OK, Lecture over...), the static command you have typed will work. The server does not have to be on the same subnet as the PIX.
 
That should work fine. It may require a couple of other rules, but you're on the right track.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top