<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515e Static NAT/DMZ Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802883#M1004767</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to make the static mapping from the high security to low security interface:&lt;/P&gt;&lt;P&gt;i.e&lt;/P&gt;&lt;P&gt;static (dmz,outside) 69.xx.yy.187 10.0.20.100 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you are allowing access from a low to high security interface you need an acl which should go as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in permit ip any host 69.xx.yy/187&lt;/P&gt;&lt;P&gt;Above allows access from any ip to your web server.&lt;/P&gt;&lt;P&gt;Regds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 May 2007 14:07:15 GMT</pubDate>
    <dc:creator>PDEdwards</dc:creator>
    <dc:date>2007-05-11T14:07:15Z</dc:date>
    <item>
      <title>PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802882#M1004764</link>
      <description>&lt;P&gt;I have a 515e, 6.3(4) with an internal interface and a DMZ. The DMZ interface  is 10.0.20.1 and the outside interface is 69.xxx.yyy.188/28&lt;/P&gt;&lt;P&gt;I have setup a web server which is currently the only device in the DMZ. I need to make a static mapping to this box but for some reason I just can't get it to work. The web server's local address is 10.0.20.100 and the public address that I need to statically map it to is 69.xxx.yyy.187/28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my config so far:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;interface ethernet2 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 dmz security50    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 69.xxx.yyy.188 255.255.255.240&lt;/P&gt;&lt;P&gt;ip address inside 192.168.20.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address dmz 10.0.20.1 255.255.255.0   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_in permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in permit ip host 69.xxx.yyy.187 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;global (dmz) 1 10.0.20.110-10.0.20.120&lt;/P&gt;&lt;P&gt;nat (inside) 1 Inside_LAN 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;nat (dmz) 1 dmz 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;static (outside,dmz) 10.0.20.100 69.xxx.yyy.187 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_in in interface outside&lt;/P&gt;&lt;P&gt;access-group dmz_in in interface dmz                        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the access-lists open for troubleshooting purposes... The global (dmz) statement is temporary so that I can access the DMZ from my inside network.&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:12:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802882#M1004764</guid>
      <dc:creator>pstebner1</dc:creator>
      <dc:date>2019-03-11T10:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802883#M1004767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to make the static mapping from the high security to low security interface:&lt;/P&gt;&lt;P&gt;i.e&lt;/P&gt;&lt;P&gt;static (dmz,outside) 69.xx.yy.187 10.0.20.100 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you are allowing access from a low to high security interface you need an acl which should go as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in permit ip any host 69.xx.yy/187&lt;/P&gt;&lt;P&gt;Above allows access from any ip to your web server.&lt;/P&gt;&lt;P&gt;Regds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 14:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802883#M1004767</guid>
      <dc:creator>PDEdwards</dc:creator>
      <dc:date>2007-05-11T14:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802884#M1004771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply-&lt;/P&gt;&lt;P&gt;I actually got that line wrong in my posting. I do have static (dmz,outside) and not the other way around.&lt;/P&gt;&lt;P&gt;I did change my access list, as you were correct with that, but it still does not work. The access-list doesn't show any hits, either.&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 14:20:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802884#M1004771</guid>
      <dc:creator>pstebner1</dc:creator>
      <dc:date>2007-05-11T14:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802885#M1004773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Post you new config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 14:29:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802885#M1004773</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-11T14:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802886#M1004775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the newer config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;interface ethernet2 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 dmz security50    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 69.xxx.yyy.188 255.255.255.240&lt;/P&gt;&lt;P&gt;ip address inside 192.168.20.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address dmz 10.0.20.1 255.255.255.0   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_in permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in permit ip any host 69.xxx.yyy.187&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;global (dmz) 1 10.0.20.110-10.0.20.120&lt;/P&gt;&lt;P&gt;nat (inside) 1 Inside_LAN 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;nat (dmz) 1 dmz 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;static (dmz,outside) 69.xxx.yyy.187 10.0.20.100 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_in in interface outside&lt;/P&gt;&lt;P&gt;access-group dmz_in in interface dmz                        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 14:37:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802886#M1004775</guid>
      <dc:creator>pstebner1</dc:creator>
      <dc:date>2007-05-11T14:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802887#M1004778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nothing wrong there, clear xlate?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 14:51:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802887#M1004778</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-11T14:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802888#M1004780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did it. Still no dice. That's why I'm so confused!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 14:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802888#M1004780</guid>
      <dc:creator>pstebner1</dc:creator>
      <dc:date>2007-05-11T14:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802889#M1004782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried using the interface ip instead just to see if that works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in permit ip any interface outside &lt;/P&gt;&lt;P&gt;static (dmz,outside) interface 10.0.20.100 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 15:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802889#M1004782</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-11T15:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802890#M1004784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This PIX is actually in production right now, and there's no chance that I can do that, at least during business hours...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 15:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802890#M1004784</guid>
      <dc:creator>pstebner1</dc:creator>
      <dc:date>2007-05-11T15:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802891#M1004787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are trying to hit 69.xxx.yyy.187 from outside the firewall right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 15:51:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802891#M1004787</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-11T15:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802892#M1004790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. I'm not THAT much of a newbie!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When inside of the network, however, I notice that as soon as I put in the static command the server loses internet access. It works fine with PAT, but of course then it isn't accessible from the outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 16:22:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802892#M1004790</guid>
      <dc:creator>pstebner1</dc:creator>
      <dc:date>2007-05-11T16:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802893#M1004791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Haha, no offense you never know who you're dealing with. There was a similar post here within the last few days. I believe it was an arp issue on the isp router. Something to consider.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 16:26:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802893#M1004791</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-11T16:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802894#M1004793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It shouldn't make a difference but you do have overlapping NAT statements ie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface &lt;/P&gt;&lt;P&gt;nat (dmz) 1 dmz 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;static (dmz,outside) 69.xxx.yyy.187 10.0.20.100 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the web server is the only device in the DMZ could you not just remove your &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat(dmz) 1 dmz 255.255.255.0 0 0 statement. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 16:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802894#M1004793</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-05-11T16:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802895#M1004795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, I know. I had that there because if I remove the static statement then I can get internet access on the box.&lt;/P&gt;&lt;P&gt;One thing that I just noticed - not sure if it makes a difference - on my internet router if I do a sh ip arp I see the arp from .187 as being incomplete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 16:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802895#M1004795</guid>
      <dc:creator>pstebner1</dc:creator>
      <dc:date>2007-05-11T16:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e Static NAT/DMZ Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802896#M1004799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mr. Comiskey-&lt;/P&gt;&lt;P&gt;Thanks for all of your help. You actually pointed me in the right direction to find the answer: The other guy that had this issue fixed it by turning on proxyarp. Worked for me too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no sysopt noproxyarp outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There it was, all along.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 19:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-static-nat-dmz-issue/m-p/802896#M1004799</guid>
      <dc:creator>pstebner1</dc:creator>
      <dc:date>2007-05-11T19:19:34Z</dc:date>
    </item>
  </channel>
</rss>

