<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAT with PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237572#M566869</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using the IP address of the external interface of the PIX to connect to from the Internet. A rule allowing ANY from OUTSIDE to the IP of the OUTSIDE interface for this port is not allowed. When creating a rule allowing traffic from ANY source on the Internet to the IP I am using on the DMZ, a 10.5.x.x address. This rule still does not give me a connection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Apr 2004 13:55:45 GMT</pubDate>
    <dc:creator />
    <dc:date>2004-04-06T13:55:45Z</dc:date>
    <item>
      <title>PAT with PIX</title>
      <link>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237568#M566865</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Currently we have a small DMZ running it's own IP range and the addresses are running out. To overcome this problem we are moving to using PAT with the outside interface IP. The end goal is to provide services spread out over three servers in the DMZ by using 1 IP address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have started with the port for mail but I cannot get it to work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The book tells me to add the following line&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp ip_outside 25 ip_dmz 25 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I add this line using the CLI it shows up the GUI. But a connection to the ip_outside:25 gives me nothing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No luck even when I make a rule allowing traffic to the ip_dmz:25 from ANY OUTSIDE source.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I missing?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237568#M566865</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2020-02-21T07:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: PAT with PIX</title>
      <link>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237569#M566866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you still need to open the port in the access list bound to the outside interface,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2004 10:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237569#M566866</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2004-04-06T10:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: PAT with PIX</title>
      <link>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237570#M566867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the answer. So you saying that besides the static mapping you need to create a rule allowing traffic from ANY OUTSIDE source to the IP ADDRESS of the server. I cannot make a rule allowing ANY SOURCE on the outside to the IP address of the OUTSIDE interface, but I can to the IP of the server in the DMZ. But no luck yet. I will try again and let you know. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2004 11:42:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237570#M566867</guid>
      <dc:creator />
      <dc:date>2004-04-06T11:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: PAT with PIX</title>
      <link>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237571#M566868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need to allow from any to the port of the service on the ip that you are using. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2004 13:07:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237571#M566868</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2004-04-06T13:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: PAT with PIX</title>
      <link>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237572#M566869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using the IP address of the external interface of the PIX to connect to from the Internet. A rule allowing ANY from OUTSIDE to the IP of the OUTSIDE interface for this port is not allowed. When creating a rule allowing traffic from ANY source on the Internet to the IP I am using on the DMZ, a 10.5.x.x address. This rule still does not give me a connection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2004 13:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pat-with-pix/m-p/237572#M566869</guid>
      <dc:creator />
      <dc:date>2004-04-06T13:55:45Z</dc:date>
    </item>
  </channel>
</rss>

