<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix515E does not allow any additional servers/hosts to be de in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861014#M954940</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So let me rephrase and correct me if I am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server X WAS! located at intf2 with an IP of 203.127.128.207/26 and now you moved it to inside interface. If correct,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Assign this server a public IP in 203.127.128.128/26 subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Change the gateway of this server from 203.127.218.193 to 203.127.218.129&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Run clear xlate and clear arp command in PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Run arp -d in command line of server for 4-5 times&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now here is the issue&lt;/P&gt;&lt;P&gt;"Outside hosts/ Internet users are not able to reach the new server "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have the following acl&lt;/P&gt;&lt;P&gt;access-list 111 permit tcp any host 203.127.218.207 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now change this acl for the new IP address that you assigned Server X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 17 Feb 2008 17:03:10 GMT</pubDate>
    <dc:creator>Alan Huseyin Kayahan</dc:creator>
    <dc:date>2008-02-17T17:03:10Z</dc:date>
    <item>
      <title>Pix515E does not allow any additional servers/hosts to be deployed</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861006#M954930</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;I have a scenario.&lt;/P&gt;&lt;P&gt;1. We are using Pix515E with Restricted license&lt;/P&gt;&lt;P&gt;2. Currently we have moved 9 servers behing the pix firewall&lt;/P&gt;&lt;P&gt;3. Now we are planning to move additional servers, but somehow pix does not allow it&lt;/P&gt;&lt;P&gt;4. NAT translations are ok&lt;/P&gt;&lt;P&gt;5. Configs has been verified to be ok&lt;/P&gt;&lt;P&gt;6. ACL are allowed&lt;/P&gt;&lt;P&gt;7. Inside servers can ping and reach/ browse the new webserver&lt;/P&gt;&lt;P&gt;8. New webserver is able to ping other inside servers and gateway-pix firewall&lt;/P&gt;&lt;P&gt;9. Outside hosts/ Internet users are not able to reach the new server&lt;/P&gt;&lt;P&gt;10. Pix logs does not shows anythings suspicious&lt;/P&gt;&lt;P&gt;11. Capture shows the ack is just not happening&lt;/P&gt;&lt;P&gt;12. We have tried to reboot / reapply the configs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please help to advise, what may be wrong&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861006#M954930</guid>
      <dc:creator>prasey</dc:creator>
      <dc:date>2019-03-11T12:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861007#M954931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prasanna&lt;/P&gt;&lt;P&gt;  Please post your running config and output of   sh ver   command.&lt;/P&gt;&lt;P&gt;  "Now we are planning to move additional servers, but somehow pix does not allow it "&lt;/P&gt;&lt;P&gt;Can you describe this please? What error do you encounter?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 18:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861007#M954931</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-02-15T18:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861008#M954932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;Thanks for reply. &lt;/P&gt;&lt;P&gt;Heres the running config edited before posting &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I could see the NAT translations happening&lt;/P&gt;&lt;P&gt;Required traffic is allowed on the firewall&lt;/P&gt;&lt;P&gt;We are currently moving a server in this setup behind the pix firewall.&lt;/P&gt;&lt;P&gt;Existing servers in this network could access the new server&lt;/P&gt;&lt;P&gt;But Internet users/ from outside interface we are unable to reach this server&lt;/P&gt;&lt;P&gt;Even from router I am unable to ping this server, though I have tried allowing the icmp from the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(3)&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;interface ethernet2 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 intf2 security80&lt;/P&gt;&lt;P&gt;hostname pix&lt;/P&gt;&lt;P&gt;clock timezone utc+8 &lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol http 8080&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list 110 permit icmp any any &lt;/P&gt;&lt;P&gt;access-list 110 permit tcp 200.x.x.x 255.255.255.192 any &lt;/P&gt;&lt;P&gt;access-list 110 permit tcp 200.x.x.x 255.255.255.192 250.x.x.x 255.255.255.192&lt;/P&gt;&lt;P&gt;access-list 111 permit icmp host 192.168.1.1 any &lt;/P&gt;&lt;P&gt;access-list 111 permit tcp any 200.x.x.x 255.255.255.192&lt;/P&gt;&lt;P&gt;access-list 111 permit tcp any 250.x.x.x 255.255.255.192&lt;/P&gt;&lt;P&gt;access-list 112 permit icmp any any &lt;/P&gt;&lt;P&gt;access-list 112 permit tcp 250.x.x.x 255.255.255.192 any &lt;/P&gt;&lt;P&gt;access-list 112 permit tcp 250.x.x.x 255.255.255.192 200.x.x.x 255.255.255.192&lt;/P&gt;&lt;P&gt;no pager&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging standby&lt;/P&gt;&lt;P&gt;logging buffered warnings&lt;/P&gt;&lt;P&gt;logging trap warnings&lt;/P&gt;&lt;P&gt;logging history errors&lt;/P&gt;&lt;P&gt;logging device-id hostname&lt;/P&gt;&lt;P&gt;logging host inside 192.168.150.10&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu intf2 1500&lt;/P&gt;&lt;P&gt;ip address outside 192.168.1.2 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address inside 200.x.x.x 255.255.255.192&lt;/P&gt;&lt;P&gt;ip address intf2 250.x.x.x 255.255.255.192&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm logging informational 100&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;static (intf2,outside) 250.x.x.x 250.x.x.x netmask 255.255.255.192 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) 200.x.x.x 200.x.x.x netmask 255.255.255.192 0 0 &lt;/P&gt;&lt;P&gt;static (inside,intf2) 200.x.x.x 200.x.x.x netmask 255.255.255.192 0 0 &lt;/P&gt;&lt;P&gt;access-group 111 in interface outside&lt;/P&gt;&lt;P&gt;access-group 110 in interface inside&lt;/P&gt;&lt;P&gt;access-group 112 in interface intf2&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1&lt;/P&gt;&lt;P&gt;route inside 192.168.150.0 255.255.255.0 200.x.x.130 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;snmp-server location xxx&lt;/P&gt;&lt;P&gt;snmp-server contact xxx&lt;/P&gt;&lt;P&gt;snmp-server community xxx&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:dc9d7ae796879bf7eacbc082387f2db9&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 19:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861008#M954932</guid>
      <dc:creator>prasey</dc:creator>
      <dc:date>2008-02-15T19:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861009#M954933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; show version&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco PIX Firewall Version 6.3(3)&lt;/P&gt;&lt;P&gt;Cisco PIX Device Manager Version 3.0(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Wed 13-Aug-03 13:55 by morlee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix up 2 hours 25 mins&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:   PIX-515E, 64 MB RAM, CPU Pentium II 433 MHz&lt;/P&gt;&lt;P&gt;Flash E28F128J3 @ 0x300, 16MB&lt;/P&gt;&lt;P&gt;BIOS Flash AM29F400B @ 0xfffd8000, 32KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encryption hardware device : Crypto5823 (revision 0x1)&lt;/P&gt;&lt;P&gt;0: ethernet0: address is 0011.2164.3c0a, irq 10&lt;/P&gt;&lt;P&gt;1: ethernet1: address is 0011.2164.3c0b, irq 11&lt;/P&gt;&lt;P&gt;2: ethernet2: address is 000d.88ee.8ec0, irq 11&lt;/P&gt;&lt;P&gt;Licensed Features:&lt;/P&gt;&lt;P&gt;Failover:                    Disabled&lt;/P&gt;&lt;P&gt;VPN-DES:                     Enabled&lt;/P&gt;&lt;P&gt;VPN-3DES-AES:                Enabled&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces: 3&lt;/P&gt;&lt;P&gt;Maximum Interfaces:          5&lt;/P&gt;&lt;P&gt;Cut-through Proxy:           Enabled&lt;/P&gt;&lt;P&gt;Guards:                      Enabled&lt;/P&gt;&lt;P&gt;URL-filtering:               Enabled&lt;/P&gt;&lt;P&gt;Inside Hosts:                Unlimited&lt;/P&gt;&lt;P&gt;Throughput:                  Unlimited&lt;/P&gt;&lt;P&gt;IKE peers:                   Unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This PIX has a Restricted (R) license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serial Number: 808549223 (0x302c27bb)&lt;/P&gt;&lt;P&gt;Running Activation Key: 0x18eaa253 0x445d4e76 0x4a743bdc 0x2ec5df9c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Heres the capture logs for the new server captured on the outside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;00:40:48.749549 157.233.234.4.59474 &amp;gt; 250.x.x.207.80: S 2108858885:2108858885(0) win 65535 &lt;MSS 1460=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 19:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861009#M954933</guid>
      <dc:creator>prasey</dc:creator>
      <dc:date>2008-02-15T19:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861010#M954935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;x.x.x es makes it hard to understand. Can you attach as a file (attached files exipre in time) . What is your inside server IP? (with subnetmask) Are 200.x.x.x public IPs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Feb 2008 00:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861010#M954935</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-02-16T00:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861011#M954936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;P&gt;I am attaching the configs, only deleting the object-groups. All other configs are intact.&lt;/P&gt;&lt;P&gt;Deleting object-group is just to shorten the cli, as we have a huge number of ip's under object-groups.&lt;/P&gt;&lt;P&gt;Yes, inside server ip is 203.127.218.207/26 are public ip's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Feb 2008 01:57:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861011#M954936</guid>
      <dc:creator>prasey</dc:creator>
      <dc:date>2008-02-16T01:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861012#M954938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your time on config posting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is te issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (intf2,outside) 203.127.218.192 203.127.218.192 netmask 255.255.255.192 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) 203.127.218.128 203.127.218.128 netmask 255.255.255.192 0 0 &lt;/P&gt;&lt;P&gt;ip address inside 203.127.218.129 255.255.255.192&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to above lines, I understand that this server was previously located at intf2 because as you see 203.127.218.207/26 does not belong to 203.127.218.128/26. You have two options&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Change the server ip in a range of defined static above (between 203.127.218.128-203.127.218.190) (Recommended)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) We have to make a huge change in config to be able to keep 207 in inside if it is a must not to change the IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Feb 2008 15:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861012#M954938</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-02-16T15:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861013#M954939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, Indeed server 203.127.218.207/26 belongs to intf2 and subnet 203.127.218.192/26 and will remain there. We have tried moving to subnet 203.127.218.128/26 still the same results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As we are using ver6.3, NAT0 alone is not sufficient, hence we are using static nat and could see the nat translations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config:-&lt;/P&gt;&lt;P&gt;ip address intf2 203.127.218.193 255.255.255.192&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Feb 2008 02:28:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861013#M954939</guid>
      <dc:creator>prasey</dc:creator>
      <dc:date>2008-02-17T02:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861014#M954940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So let me rephrase and correct me if I am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server X WAS! located at intf2 with an IP of 203.127.128.207/26 and now you moved it to inside interface. If correct,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Assign this server a public IP in 203.127.128.128/26 subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Change the gateway of this server from 203.127.218.193 to 203.127.218.129&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Run clear xlate and clear arp command in PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Run arp -d in command line of server for 4-5 times&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now here is the issue&lt;/P&gt;&lt;P&gt;"Outside hosts/ Internet users are not able to reach the new server "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have the following acl&lt;/P&gt;&lt;P&gt;access-list 111 permit tcp any host 203.127.218.207 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now change this acl for the new IP address that you assigned Server X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Feb 2008 17:03:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861014#M954940</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-02-17T17:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861015#M954941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your efforts sir!&lt;/P&gt;&lt;P&gt;These has been tried before, and found to be not working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rephrasing the problem:-&lt;/P&gt;&lt;P&gt;If I add new servers either in Inside int or intf2, it does not work. Existing servers are working fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For testing, I brought down one of the production servers, and used its ip for the new test server. Now the new test server works. But with the new ip, say in .128 or .192 subnet, the new servers does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2008 09:43:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861015#M954941</guid>
      <dc:creator>prasey</dc:creator>
      <dc:date>2008-02-18T09:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861016#M954942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Big THANKS to husycisco !&lt;/P&gt;&lt;P&gt;I have figured out the problem now. Unfortunately all the 3 test servers we had been using to test were faulty in a way or other. either nic card, or image .... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your effort and time sir.&lt;/P&gt;&lt;P&gt;Highly appreciate your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2008 03:35:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861016#M954942</guid>
      <dc:creator>prasey</dc:creator>
      <dc:date>2008-02-20T03:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: Pix515E does not allow any additional servers/hosts to be de</title>
      <link>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861017#M954943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad that you sorted it out &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2008 04:01:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix515e-does-not-allow-any-additional-servers-hosts-to-be/m-p/861017#M954943</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-02-20T04:01:39Z</dc:date>
    </item>
  </channel>
</rss>

