<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Interfacemanagment on a PIX515e in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/interfacemanagment-on-a-pix515e/m-p/2175634#M356997</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should be possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You have a small link network between your PIX and your ISP.&lt;/LI&gt;&lt;LI&gt;The ISP routes either a small public subnet or host addresses towards your PIX "outside" interface IP address&lt;/LI&gt;&lt;LI&gt;You configure Static/Dynamic NAT/PAT on the PIX like usual&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the ASA firewalls and new software levels 8.3/8.4 there have been some setups that have been problematic because of changes to the software BUT to my understanding this setup should be ok in your case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Feb 2013 14:58:27 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-02-07T14:58:27Z</dc:date>
    <item>
      <title>Interfacemanagment on a PIX515e</title>
      <link>https://community.cisco.com/t5/network-security/interfacemanagment-on-a-pix515e/m-p/2175633#M356996</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Client is changing ISPs'. They currently have a x.x.x.x/28 network and they are using 10 of the available IPs'. The new provider wants to give them a /30 network, 1 IP for the Outside interface and the other will be their equipment, my gateway. And then redirect specific address, /32, as needed to the PIX for my remaining outside Static IP needs. The PIX is only licensed for 3 Maximum Physical Interfaces. Am I correct in thinking that the PIX will not support this configuration?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interfacemanagment-on-a-pix515e/m-p/2175633#M356996</guid>
      <dc:creator>rcrampton</dc:creator>
      <dc:date>2019-03-12T00:57:15Z</dc:date>
    </item>
    <item>
      <title>Interfacemanagment on a PIX515e</title>
      <link>https://community.cisco.com/t5/network-security/interfacemanagment-on-a-pix515e/m-p/2175634#M356997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should be possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You have a small link network between your PIX and your ISP.&lt;/LI&gt;&lt;LI&gt;The ISP routes either a small public subnet or host addresses towards your PIX "outside" interface IP address&lt;/LI&gt;&lt;LI&gt;You configure Static/Dynamic NAT/PAT on the PIX like usual&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the ASA firewalls and new software levels 8.3/8.4 there have been some setups that have been problematic because of changes to the software BUT to my understanding this setup should be ok in your case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 14:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interfacemanagment-on-a-pix515e/m-p/2175634#M356997</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-07T14:58:27Z</dc:date>
    </item>
    <item>
      <title>Interfacemanagment on a PIX515e</title>
      <link>https://community.cisco.com/t5/network-security/interfacemanagment-on-a-pix515e/m-p/2175635#M356998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The interface is currently configured as:&lt;/P&gt;&lt;P&gt; interface Ethernet0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address x.x.x.62 255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This gives me x.x.x.49-62 as usable interfaces. And by subnetting rules, Ethernet0 knows the addresses within that range are on it's network. I have at least 10 Statics in use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The New config will look like:&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address x.x.x.226 255.255.255.252&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure how I can staticly map to a x.x.x.230 255.255.255.255 outside of the Ethernet0 network?!?!?!?!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; width: 1px; height: 1px; overflow: hidden; top: 0px; left: -10000px;"&gt;﻿&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 15:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interfacemanagment-on-a-pix515e/m-p/2175635#M356998</guid>
      <dc:creator>rcrampton</dc:creator>
      <dc:date>2013-02-07T15:20:29Z</dc:date>
    </item>
    <item>
      <title>Interfacemanagment on a PIX515e</title>
      <link>https://community.cisco.com/t5/network-security/interfacemanagment-on-a-pix515e/m-p/2175636#M357000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To give you an example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have several Cisco FWSMs and ASA5585-X devices that hold multiple Security Contexts (Virtual firewalls)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example one of our customers has an /29 network allocated from RIPE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This customer has now exhausted that small subnet for all his Static NATs for servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They then request for additional public IP addresses. We then route additional host IP addresses when needed towards the customer firewall "outside" interface IP address and configure the Static NAT using that new public IP on the customer firewall and make the required ACL configurations and everything works just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To give you a simple configuration on the FWSM (Firewall Services Module) and Core C6500 series device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;1.1.1.0/28 = example link network between ISP and FW&lt;/LI&gt;&lt;LI&gt;2.2.2.x / 3.3.3.x = example additional IP addresses assigned by ISP when the above link networks addresses were exhausted&lt;/LI&gt;&lt;LI&gt;Vlan3000 = In an C6500 + FWSM&amp;nbsp; environment simply the link network/interface interface between the FW and ISP GW&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Core Router&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan3000&lt;/P&gt;&lt;P&gt; description Customer FW Outside&lt;/P&gt;&lt;P&gt; ip add 1.1.1.1 255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 2.2.2.1 255.255.255.255 1.1.1.2&lt;/P&gt;&lt;P&gt;ip route 2.2.2.2 255.255.255.255 1.1.1.2&lt;/P&gt;&lt;P&gt;ip route 3.3.3.1 255.255.255.255 1.1.1.2&lt;/P&gt;&lt;P&gt;ip route 3.3.3.2 255.255.255.255 1.1.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FWSM / Firewall Context&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan3000&lt;/P&gt;&lt;P&gt; description Customer FW Outside&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip add 1.1.1.2 255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.10.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 2 1.1.1.3&lt;/P&gt;&lt;P&gt;nat (inside) 2 10.10.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.1.4 10.10.10.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.1.5 10.10.20.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 2.2.2.1 10.10.10.11 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) 3.3.3.1 10.10.20.11 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And so on..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 16:36:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interfacemanagment-on-a-pix515e/m-p/2175636#M357000</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-07T16:36:25Z</dc:date>
    </item>
  </channel>
</rss>

