<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help with Translation Rule on PIX 506E in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-with-translation-rule-on-pix-506e/m-p/58585#M677071</link>
    <description>&lt;P&gt;  I have a network connected to DSL via an 847 Router.  We are adding a PIX firewall and I am a little confused about the translation rule for the email server.&lt;/P&gt;&lt;P&gt;  Currently we have a pubic (static) IP assigned to the ATM interface of the router, and have 10.0.0.1 assigned on the router's LAN side.  My plan is to assign 10.0.0.5 to the outside interface of the PIX, use 192.168.1.5 for the inside interface and then use the 192.168.1.0 range for my PC's/Server.  My question is, should I translate the inside address of my email server (192.168.1.10) to the address of my router/gateway (10.0.0.1)  on the unsecured side, or to my public IP address on the WAN side of the router?&lt;/P&gt;&lt;P&gt;  Any help you could give me would be greatly appreciated, as this is my first attempt at PIX configuration.  Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   ...Scott&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 06:16:37 GMT</pubDate>
    <dc:creator>scottorgan</dc:creator>
    <dc:date>2020-02-21T06:16:37Z</dc:date>
    <item>
      <title>Help with Translation Rule on PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/help-with-translation-rule-on-pix-506e/m-p/58585#M677071</link>
      <description>&lt;P&gt;  I have a network connected to DSL via an 847 Router.  We are adding a PIX firewall and I am a little confused about the translation rule for the email server.&lt;/P&gt;&lt;P&gt;  Currently we have a pubic (static) IP assigned to the ATM interface of the router, and have 10.0.0.1 assigned on the router's LAN side.  My plan is to assign 10.0.0.5 to the outside interface of the PIX, use 192.168.1.5 for the inside interface and then use the 192.168.1.0 range for my PC's/Server.  My question is, should I translate the inside address of my email server (192.168.1.10) to the address of my router/gateway (10.0.0.1)  on the unsecured side, or to my public IP address on the WAN side of the router?&lt;/P&gt;&lt;P&gt;  Any help you could give me would be greatly appreciated, as this is my first attempt at PIX configuration.  Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   ...Scott&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:16:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-translation-rule-on-pix-506e/m-p/58585#M677071</guid>
      <dc:creator>scottorgan</dc:creator>
      <dc:date>2020-02-21T06:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Translation Rule on PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/help-with-translation-rule-on-pix-506e/m-p/58586#M677072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there's a couple of ways for you to set it up.&lt;/P&gt;&lt;P&gt;If the port translation through the router is 10.0.0.10 on port 25 at the moment, when the pix is in place and address changes made as planned, simply add a static translation / ACL on the pix for the new address eg&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.0.0.10 192.168.1.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list in_out permit tcp any host 192.168.1.10 eq smtp&lt;/P&gt;&lt;P&gt;access-group in_out in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The static will allow traffic from the mail server going out to translate to its original ip address requiring no further config on the router apart from clearing arp. Inbound traffic to the server will be natted through the router as before but now the pix will proxy arp for the server (192.168.1.10) on 10.0.0.10. So long as the routing is up to scratch, should all work fine.&lt;/P&gt;&lt;P&gt;This is the easiest way so won't even mention anything else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Sep 2002 12:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-translation-rule-on-pix-506e/m-p/58586#M677072</guid>
      <dc:creator>turnbull</dc:creator>
      <dc:date>2002-09-29T12:07:10Z</dc:date>
    </item>
  </channel>
</rss>

