cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1443
Views
5
Helpful
15
Replies

NAT help

brandon.hodge
Level 1
Level 1

I'm having an issue working with a PIX 7.0 that has lots of history. There is a ton of entries like below:

static (inside,outside) 192.168.1.0 192.168.1.0 netmask 255.255.255.0

I'm trying to make one ip address on that subnet come out as the firewall external IP. I have the global (outside) 1 interface set up with the nat (inside) 1 192.168.1.5. This doesn't work unless I pull out the static entry for the entire subnet.

The main problem I'm having is for some reasos when I pull out the static that has the subnet. Without the static entry the subnet comes out with an address other than itself. What does the PIX do for an address that doesn't have a static or global entry set up?

15 Replies 15

Hi,

Would seem correct to me.

Though personally I have never really had the need to change the "nat-control" setting. Though usually when I am doing some change that I have uncertainty I lab it or do the change during hours where any possible problem wouldnt cause much issues for users.

Here is a link to a Cisco document about "nat-control" setting

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_control.html#wp1082396

- Jouni

Review Cisco Networking for a $25 gift card