<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Host on DMZ with Public IP - Advice Please. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/host-on-dmz-with-public-ip-advice-please/m-p/628940#M1031769</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With the static you have in place, your routing the IP, not translating it. Since the server has an IP of 172.25.1.1, you'll need a different translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz1,outside) 82.7.58.234 172.25.1.1 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH and please rate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Jan 2007 22:20:38 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2007-01-15T22:20:38Z</dc:date>
    <item>
      <title>Host on DMZ with Public IP - Advice Please.</title>
      <link>https://community.cisco.com/t5/network-security/host-on-dmz-with-public-ip-advice-please/m-p/628939#M1031768</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would be grateful if anyone can enlighten me with regards to placing a server with a public IP within a DMZ on a PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am relatively familar with static translations, those mapping public IPs to internal hosts but I have never had a host within a DMZ with a public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used the command;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz1,outside) 82.7.58.234 82.7.56.234 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;combined with an ACL on the outside interface to allow connections in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However after doing this the server does not seem reachable.  The DMZ interface IP is 172.25.1.1 and I am scratching my head as to whether it is routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was expecting the PIX to have the intelligence to know that the server was on the DMZ due to the static statement and just map straight to it -  maybe I am wrong??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything else I need to add ?  Do I need to 'nat (dmz1) 0 82.7.58.234' ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:19:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-on-dmz-with-public-ip-advice-please/m-p/628939#M1031768</guid>
      <dc:creator>Purist1972</dc:creator>
      <dc:date>2019-03-11T09:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Host on DMZ with Public IP - Advice Please.</title>
      <link>https://community.cisco.com/t5/network-security/host-on-dmz-with-public-ip-advice-please/m-p/628940#M1031769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With the static you have in place, your routing the IP, not translating it. Since the server has an IP of 172.25.1.1, you'll need a different translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz1,outside) 82.7.58.234 172.25.1.1 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH and please rate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2007 22:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-on-dmz-with-public-ip-advice-please/m-p/628940#M1031769</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-01-15T22:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Host on DMZ with Public IP - Advice Please.</title>
      <link>https://community.cisco.com/t5/network-security/host-on-dmz-with-public-ip-advice-please/m-p/628941#M1031770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I am unclear here. Are you trying to static a public address to another public address? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my experience, I would put the host on the DMZ network (say 172.25.1.100) and then static to that (ie. static (dmz1,outside) 82.7.58.234 172.25.1.100 netmask 255.255.255.255 ) then you could do nat (dmz1) 1 0.0.0.0 0.0.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Brandon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2007 22:26:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-on-dmz-with-public-ip-advice-please/m-p/628941#M1031770</guid>
      <dc:creator>gecko2207</dc:creator>
      <dc:date>2007-01-15T22:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: Host on DMZ with Public IP - Advice Please.</title>
      <link>https://community.cisco.com/t5/network-security/host-on-dmz-with-public-ip-advice-please/m-p/628942#M1031771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Donald,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to do something like Brandon suggested above. Firewall aside, you can't have a device on a subnet that's different from the gateway's (fw) subnet as they can't talk to each other. Hence, your server can't be on a public NET while the DMZ subnet, the server physically resides on, is on a private NET as it would break IP communication between the firewall and the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2007 22:49:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-on-dmz-with-public-ip-advice-please/m-p/628942#M1031771</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2007-01-15T22:49:44Z</dc:date>
    </item>
  </channel>
</rss>

