<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX doesn't NAT outbound packets to correct IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-doesn-t-nat-outbound-packets-to-correct-ip/m-p/881588#M973947</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 515E running v6.1(2).  The firewall has an external and internal interface only.  The webservers and mail server are behind the firewall on the internal network.  We have 1 external address reserved for all outbound connections from PCs.  I have several static configurations set for inbound connections to the web and mail servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The mail server is using an external address of XXX.XXX.XXX.105 which the PIX passes through to my internal address of XXX.XXX.XXX.24.  The outbound connections from XXX.XXX.XXX.24 end up using the external address of XXX.XXX.XXX.109.  I need it to use the 105 address so other mailservers will accept our emails.  I understand from my reading is that all I need is the static config and an access-list entry for outbound-in connections to make it all possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I doing wrong?  Any information would be appreciated. Following is the relevant config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;name XXX.XXX.XX6.109 extnat&lt;/P&gt;&lt;P&gt;name XXX.XXX.XX6.105 extmail&lt;/P&gt;&lt;P&gt;name XXX.XXX.XX8.24 intmail&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;access-list 111 permit tcp any host extmail eq smtp&lt;/P&gt;&lt;P&gt;access-list 211 permit ip XXX.XXX.XX8.0 255.255.255.0 XXX.XXX.X10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 extnat&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 211&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;static (inside, outside) extmail intmail netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;access-group 111 in interface outside&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:21:04 GMT</pubDate>
    <dc:creator>tshooter91</dc:creator>
    <dc:date>2019-03-11T11:21:04Z</dc:date>
    <item>
      <title>PIX doesn't NAT outbound packets to correct IP</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-nat-outbound-packets-to-correct-ip/m-p/881588#M973947</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 515E running v6.1(2).  The firewall has an external and internal interface only.  The webservers and mail server are behind the firewall on the internal network.  We have 1 external address reserved for all outbound connections from PCs.  I have several static configurations set for inbound connections to the web and mail servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The mail server is using an external address of XXX.XXX.XXX.105 which the PIX passes through to my internal address of XXX.XXX.XXX.24.  The outbound connections from XXX.XXX.XXX.24 end up using the external address of XXX.XXX.XXX.109.  I need it to use the 105 address so other mailservers will accept our emails.  I understand from my reading is that all I need is the static config and an access-list entry for outbound-in connections to make it all possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I doing wrong?  Any information would be appreciated. Following is the relevant config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;name XXX.XXX.XX6.109 extnat&lt;/P&gt;&lt;P&gt;name XXX.XXX.XX6.105 extmail&lt;/P&gt;&lt;P&gt;name XXX.XXX.XX8.24 intmail&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;access-list 111 permit tcp any host extmail eq smtp&lt;/P&gt;&lt;P&gt;access-list 211 permit ip XXX.XXX.XX8.0 255.255.255.0 XXX.XXX.X10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 extnat&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 211&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;static (inside, outside) extmail intmail netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;access-group 111 in interface outside&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-nat-outbound-packets-to-correct-ip/m-p/881588#M973947</guid>
      <dc:creator>tshooter91</dc:creator>
      <dc:date>2019-03-11T11:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't NAT outbound packets to correct IP</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-nat-outbound-packets-to-correct-ip/m-p/881589#M973948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The configuration looks good. After you added the static did you do a 'clear xlate' for the static to take effect?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2007 19:36:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-nat-outbound-packets-to-correct-ip/m-p/881589#M973948</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2007-10-04T19:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't NAT outbound packets to correct IP</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-nat-outbound-packets-to-correct-ip/m-p/881590#M973949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did as you suggested and I'm not getting bounced emails any more, so that must've fixed it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Come to think of it, the mail server _was_ moved to different hardware, so maybe something with the MAC address was still hung up in the translation tables?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the fix.  A reload of the PIX didn't work, but running that command did.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2007 15:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-nat-outbound-packets-to-correct-ip/m-p/881590#M973949</guid>
      <dc:creator>tshooter91</dc:creator>
      <dc:date>2007-10-05T15:53:57Z</dc:date>
    </item>
  </channel>
</rss>

