<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX Static Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-static-problem/m-p/121128#M614161</link>
    <description>&lt;P&gt;We are using a parameter interface PIX 520.Problem is that here.&lt;/P&gt;&lt;P&gt;1. Already defined a static entry &lt;/P&gt;&lt;P&gt;static (inside,outside) 203.125.152.243 172.16.206.21 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;2.want to allow a WAN link with IP's 172.17.0.0/16 to pass through PIX transparent ( outside ) &amp;amp; access the inside IP server 172.16.206.21.&lt;/P&gt;&lt;P&gt;Solution used : NAT 0....I can ping and traceroute both the outside IP's 172.20.23.51 etc from inside but cannot connect to the server application as there is an already defined static defined and we cannot have 2nd static like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static ( inside,outisde ) 172.16.206.21 172.16.206.21 netmask 255.255.255.255 0 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list GPRSNONAT permit ip host 172.16.206.21 host 172.20.23.51&lt;/P&gt;&lt;P&gt;access-list GPRSNONAT permit ip host 172.16.206.21 host 172.20.10.66&lt;/P&gt;&lt;P&gt;access-list GPRSNONAT permit ip host 172.16.206.21 host 172.21.21.1&lt;/P&gt;&lt;P&gt;access-list GPRSNONAT permit ip host 172.16.206.21 host 172.21.21.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list GPRSNONAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 203.125.152.243 172.16.206.21 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be a great favor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 06:46:43 GMT</pubDate>
    <dc:creator>damomann</dc:creator>
    <dc:date>2020-02-21T06:46:43Z</dc:date>
    <item>
      <title>PIX Static Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-static-problem/m-p/121128#M614161</link>
      <description>&lt;P&gt;We are using a parameter interface PIX 520.Problem is that here.&lt;/P&gt;&lt;P&gt;1. Already defined a static entry &lt;/P&gt;&lt;P&gt;static (inside,outside) 203.125.152.243 172.16.206.21 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;2.want to allow a WAN link with IP's 172.17.0.0/16 to pass through PIX transparent ( outside ) &amp;amp; access the inside IP server 172.16.206.21.&lt;/P&gt;&lt;P&gt;Solution used : NAT 0....I can ping and traceroute both the outside IP's 172.20.23.51 etc from inside but cannot connect to the server application as there is an already defined static defined and we cannot have 2nd static like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static ( inside,outisde ) 172.16.206.21 172.16.206.21 netmask 255.255.255.255 0 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list GPRSNONAT permit ip host 172.16.206.21 host 172.20.23.51&lt;/P&gt;&lt;P&gt;access-list GPRSNONAT permit ip host 172.16.206.21 host 172.20.10.66&lt;/P&gt;&lt;P&gt;access-list GPRSNONAT permit ip host 172.16.206.21 host 172.21.21.1&lt;/P&gt;&lt;P&gt;access-list GPRSNONAT permit ip host 172.16.206.21 host 172.21.21.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list GPRSNONAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 203.125.152.243 172.16.206.21 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be a great favor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:46:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-static-problem/m-p/121128#M614161</guid>
      <dc:creator>damomann</dc:creator>
      <dc:date>2020-02-21T06:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Static Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-static-problem/m-p/121129#M614162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I understand your problem correctly I think the solution is to use Destination NAT.  Here's an example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;alias(inside) 203.125.152.243 172.16.206.21 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information refer to the section in this link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094aee.shtml#dmz" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094aee.shtml#dmz&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Cody Rowland&lt;/P&gt;&lt;P&gt;Infrastructure Engineer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2003 11:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-static-problem/m-p/121129#M614162</guid>
      <dc:creator>cody.rowland</dc:creator>
      <dc:date>2003-06-03T11:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Static Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-static-problem/m-p/121130#M614163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That static statement is fine.  Based on your info in items 1 and 2 above, your ACL should look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list GPRSNONAT permit ip  host 172.16.206.21 172.17.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You also need an ACL to allow the traffic in:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside permit ip 172.17.0.0 255.255.0.0 host 172.16.206.2&lt;/P&gt;&lt;P&gt;access-group outside in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WAN IPs you reference in item #2 above don't match the other IPs you mention and reference in the nat0 ACL.&lt;/P&gt;&lt;P&gt;access-group outside in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After all changes are made, you must perform a [clear xlate local 172.16.206.21].&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2003 13:06:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-static-problem/m-p/121130#M614163</guid>
      <dc:creator>shannong</dc:creator>
      <dc:date>2003-06-03T13:06:22Z</dc:date>
    </item>
  </channel>
</rss>

