Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

static with global & nat

Status
Not open for further replies.

jlmk

MIS
Feb 1, 2001
12
HK
I have a question on PIX firewall as below:

There is a network 223.11.50.0 need to access to one host 10.80.0.1. I can use the global & nat command that allows the PAT mapping.
global (outside) 1 10.80.0.2 netmask 255.255.255.255
nat (inside) 1 223.11.50.0 255.255.255.0 0 0

However 2 pcs within the subnet need to identically map to 2 different global address:
223.11.50.55 -> 10.80.0.3
223.11.50.100 -> 10.80.0.4

static (inside,outside) 10.80.0.3 223.11.50.55 netmask 255.255.255.255 0 0
static (inside,outside) 10.80.0.4 223.11.50.100 netmask 255.255.255.255 0 0

Can I still use the above command e.g. global, nat, static in order to archive my objection. Is the static mapping be first run and then global, nat will be executed in lower priority. Thanks
 
I'm not sure how that would work exactly. I've always thought statics were more designed to allow inbound connections to servers behind the firewall. I think the way to do it would be

global (outside) 2 10.80.0.3
global (outside) 3 10.80.0.4
nat (inside) 2 223.11.50.55 255.255.255.255
nat (inside) 3 223.11.50.100 255.255.255.255

I think that will force each of the 2 computers requiring unique translation to their external addresses. Can someone else verify this is correct or did I miss something?

Jason
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top