<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic PAT on PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588128#M502229</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have checked your configs ..  the only option you have is a static using 219.95.73.28 which is not used as yet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 219.95.73.28 200.1.1.X netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 219.95.73.28 range 5500 5800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I see that remote access using remote desktop is allowed from the Internet. Make your customer aware that this sort of access are a security risk as usernames and passwords travel on clear text. I suggest remote VPN set up for remote access. Anyway ..  the instructions above will solve your current issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if you find this helpful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Apr 2006 07:52:32 GMT</pubDate>
    <dc:creator>Fernando_Meza</dc:creator>
    <dc:date>2006-04-24T07:52:32Z</dc:date>
    <item>
      <title>Dynamic PAT on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588120#M502217</link>
      <description>&lt;P&gt;Hi Expert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I want to Dynamic NAT port range from 5500 to 5800, into my public IP which NAT to a private IP, how to configure?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here the example,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;public IP = x.x.x.x&lt;/P&gt;&lt;P&gt;private IP = z.z.z.z&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT x.x.x.x port 5500-5800 to z.z.z.z port 5500-5800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PIX firewall is running OS 6.3(4).&lt;/P&gt;&lt;P&gt;Customer actually need to enable for ftp trffic that allow client can dynamic used port within range 5500 and 5800.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope someone can help me on this, thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Au Yeong Shaw Voel&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:51:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588120#M502217</guid>
      <dc:creator>shawvoel</dc:creator>
      <dc:date>2020-02-21T08:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588121#M502218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try following&lt;/P&gt;&lt;P&gt;static (inside,outside) x.x.x.x access-list port_map&lt;/P&gt;&lt;P&gt;access-list port_map  permit tcp any host z.z.z.z range 5500 5800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need also configure outside access-list for permiting this traffic from outside&lt;/P&gt;&lt;P&gt;so add to you access-list on outside interface following line&lt;/P&gt;&lt;P&gt;access-list out permit tcp any host x.x.x.x range 5500 5800&lt;/P&gt;&lt;P&gt;If you are also using ftp protocol on non standart ports (5500 - 5800) you maybe need command&lt;/P&gt;&lt;P&gt; fixup protocol ftp on those ports&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;P&gt;Hope that helps rate if it does&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Apr 2006 09:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588121#M502218</guid>
      <dc:creator>m.sir</dc:creator>
      <dc:date>2006-04-21T09:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588122#M502219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi M,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But why it keep prompt error,&lt;/P&gt;&lt;P&gt;ERROR: cannot translate from IP protocol tcp to IP protocol ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After I create the accee-list, when I try to key in the static command, it prompt this error.&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Au Yeong Shaw Voel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Apr 2006 05:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588122#M502219</guid>
      <dc:creator>shawvoel</dc:creator>
      <dc:date>2006-04-23T05:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588123#M502220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please paste ur access list and the static command ur tryin to issue here&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Apr 2006 07:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588123#M502220</guid>
      <dc:creator>victorrodrigues</dc:creator>
      <dc:date>2006-04-23T07:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588124#M502221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there .. I have been following your case as I have not had that requirement before ...  I believe you already posted this issue a few days ago. I don't think the range of ports is supported by an static instruction on the PIX. I have tried several combinations on a lab and it just does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think your best option will be to perform a one to one static NAT and control the filtering on the access-list applied to the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) x.x.x.x y.y.y.y netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside-in permit tcp any host x.x.x.x range 5500 5800&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Apr 2006 07:35:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588124#M502221</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-04-23T07:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588125#M502223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fernando,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I would like to do the same thing as you told but my public IP already map to different IP with different port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here I attach my configuration, the IP that I would like to map a range 5500 to 5800 is 219.95.73.30, and my private IP is 200.1.1.5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think I can do one to one mapping anymore.&lt;/P&gt;&lt;P&gt;Or you have other solution for this?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Au Yeong Shaw Voel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Apr 2006 00:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588125#M502223</guid>
      <dc:creator>shawvoel</dc:creator>
      <dc:date>2006-04-24T00:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588126#M502225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;like Fernando said... try this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 219.95.73.30 200.1.1.5 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside-in permit tcp any host 219.95.73.30 range 5500 5800&lt;/P&gt;&lt;P&gt;access-group outside-in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;make sure 219.95.73.30 is not being used in any other static commands.. best thing.. remove all other statics , just keep ur interface Pat .. &lt;/P&gt;&lt;P&gt;when searching for outbound connection . the firewall will 1st see the static.. and use that for the host 200.1.1.5 since that is an exact match... &lt;/P&gt;&lt;P&gt;should work &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then watch ur live log to see what traffic is coming thru and if indeed sessions for your ports are running &lt;/P&gt;&lt;P&gt;all the best.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will be great if u can assign points.. &lt;/P&gt;&lt;P&gt;first to fernando..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Apr 2006 04:06:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588126#M502225</guid>
      <dc:creator>victorrodrigues</dc:creator>
      <dc:date>2006-04-24T04:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588127#M502227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am on the run right now ..  will look at your config and see what other options ( if any ) you have ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Apr 2006 05:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588127#M502227</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-04-24T05:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588128#M502229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have checked your configs ..  the only option you have is a static using 219.95.73.28 which is not used as yet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 219.95.73.28 200.1.1.X netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 219.95.73.28 range 5500 5800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I see that remote access using remote desktop is allowed from the Internet. Make your customer aware that this sort of access are a security risk as usernames and passwords travel on clear text. I suggest remote VPN set up for remote access. Anyway ..  the instructions above will solve your current issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if you find this helpful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Apr 2006 07:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588128#M502229</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-04-24T07:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588129#M502231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fernando,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank. Let me try on your solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Au Yeong Shaw Voel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Apr 2006 08:15:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-on-pix/m-p/588129#M502231</guid>
      <dc:creator>shawvoel</dc:creator>
      <dc:date>2006-04-24T08:15:36Z</dc:date>
    </item>
  </channel>
</rss>

