Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

NAT-Issue with PIX

Status
Not open for further replies.

martinp05

Technical User
May 19, 2005
71
AT
Hello!

I have to solve the following problem.

On the 520er PIX i have several interfaces. Behind the DMZ-Interface i have an webserver with a private ip (citrix secure gateway). This server is available in the public internet (static on the pix).

From the INSIDE-Interface we want to use this Server for Citrix-access. When i resolve this server from the INSIDE-LAN i get the public ip for this server.

The problem is (i think), that the request to this server goes out of the pix to the internet, and then goes back to the pix to the dmz-interface...And this will not work.

My idea is, to make a nat for the puplic ip, when the request comes from the INSIDE-LAN. This nat should transfer the public-ip to the private-ip of the server located in the dmz.

I think i will not need an static, because the access goes from the higher sec-level (inside) to the lower-level (dmz).
I need to nat a pubip to an private ip from an higher sec-level to an lower-level.

But what can i do??

Martin

----------------------------------
Martin Peinsipp, Austria
CCSA,
IT-Security-Administrator
 
It depends on the version of your PIX OS. Newer versions (6.3(3) I think) allow you to use the static command to map from higher to lower. In addition to:
static (dmz,outside) <outside ip> <dmz ip>

add the following to map the public IP to your internal network:
static (dmz,inside) <outside ip> <dmz ip>

If that does not work, try the alias command (which was for older PIXes). On this command, it's better to simply read about it at:

Hope this helps!
 
hello,

thank you for your help, the static did it.

martin

----------------------------------
Martin Peinsipp, Austria
CCSA,
IT-Security-Administrator
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top