<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 7.0.4 NAT Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-7-0-4-nat-issue/m-p/448519#M528492</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;providing different static statements are used for different ports, you can configure port forwarding instead of one-to-one mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;P&gt;static (dmz,outside) tcp 172.16.1.10 9443 192.168.3.3 9443 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) tcp 172.16.1.11 9080 192.168.3.3 9080 netmask 255.255.255.255&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Jan 2006 02:47:40 GMT</pubDate>
    <dc:creator>jackko</dc:creator>
    <dc:date>2006-01-17T02:47:40Z</dc:date>
    <item>
      <title>PIX 7.0.4 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-4-nat-issue/m-p/448518#M528489</link>
      <description>&lt;P&gt;I recently upgraded from version 6.3.4 to 7.0.4 on a new PIX firewall.  Now it appears that mapping multiple outside IP addresses to a single inside IP, which was supported in 6.3.4, is not longer supported in 7.0.4.  Is this true, and if so, are there any workarounds?  Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX 6.3.4 Config&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;access-list acl_DMZ_in permit tcp 192.168.3.3 255.255.255.0 any eq 80 &lt;/P&gt;&lt;P&gt;access-list acl_DMZ_in permit tcp 192.168.3.3 255.255.255.0 any eq 443 &lt;/P&gt;&lt;P&gt;access-list acl_DMZ_in permit tcp host 192.168.3.3 host 10.250.225.25 eq 9080&lt;/P&gt;&lt;P&gt;access-list acl_DMZ_in permit tcp host 192.168.3.3 host 10.250.225.25 eq 9443&lt;/P&gt;&lt;P&gt;static (DMZ,outside) 172.16.1.10 192.168.3.3 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (DMZ,outside) 172.16.1.11 192.168.3.3 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (DMZ,outside) 172.16.1.12 192.168.3.3 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX 7.0.4 Config&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;access-list acl_DMZ_in extended permit tcp 192.168.3.3 255.255.255.0 any eq 80 &lt;/P&gt;&lt;P&gt;access-list acl_DMZ_in extended permit tcp 192.168.3.3 255.255.255.0 any eq 443 &lt;/P&gt;&lt;P&gt;access-list acl_DMZ_in extended permit tcp host 192.168.3.3 host 10.250.225.25 eq 9080&lt;/P&gt;&lt;P&gt;access-list acl_DMZ_in extended permit tcp host 192.168.3.3 host 10.250.225.25 eq 9443&lt;/P&gt;&lt;P&gt;static (DMZ,outside) 172.16.1.10 192.168.3.3 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;config term&lt;/P&gt;&lt;P&gt;static (DMZ,outside) 172.16.1.11 192.168.3.3 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;ERROR: duplicate of existing static&lt;/P&gt;&lt;P&gt;  DMZ-1:192.168.3.3 to outside:172.16.1.11 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-4-nat-issue/m-p/448518#M528489</guid>
      <dc:creator>dspdss</dc:creator>
      <dc:date>2020-02-21T08:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0.4 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-4-nat-issue/m-p/448519#M528492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;providing different static statements are used for different ports, you can configure port forwarding instead of one-to-one mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;P&gt;static (dmz,outside) tcp 172.16.1.10 9443 192.168.3.3 9443 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) tcp 172.16.1.11 9080 192.168.3.3 9080 netmask 255.255.255.255&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jan 2006 02:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-4-nat-issue/m-p/448519#M528492</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2006-01-17T02:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0.4 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-4-nat-issue/m-p/448520#M528500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've just had a response back from TAC on this exact issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;multiple to 1 NAT  is not, and has never been supported in PIX/ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wrt it previously working in 6.3.4, (and other versions.)  TAC response is  "may have worked....  but it is not guaranteed to work all the time".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jan 2006 06:54:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-4-nat-issue/m-p/448520#M528500</guid>
      <dc:creator>walter_muller</dc:creator>
      <dc:date>2006-01-17T06:54:01Z</dc:date>
    </item>
  </channel>
</rss>

