06-20-2002 03:53 AM - edited 02-20-2020 10:06 PM
Can I connect PIX 501 with 10 users license to a Network wih more than 10 PC and all accessing internet. But any time only 6-7 users will be surfing. If yes then I have a PIX which allows only the first 10 PC's which surf the net and the other PC's are denied access even if the previous PC are not using it anymore. Is there a way where I can clear the previous user if they are not surfing automatically after some time out.
06-20-2002 12:40 PM
why don't you setup a global (inside) to use it and once that exceeded users will go through the PAT.
global (inside) 1 66.xx.xx.10-66.xx.xx.19
global (inside) 1 66.xx.xx.20
hope this help
06-20-2002 08:56 PM
I don't think licence limits can be broken but that way..
I just use microsoft nat (pat) solution on MS W2K server before puting traffic through PIX and PIX thinks that I have only one PC.
06-21-2002 06:48 AM
the License is for simultaneos 10 users so in that context it should work if I manually clear the tcp list it accepts the other connections but this should be done by itself if the PC is not accessing the internet.
07-01-2002 07:29 PM
on pic code 6.2 you can set a timeout parameter for the nat
see the command reference for 6.2 :
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/cmdref/mr.htm#xtocid6 .
Regards,
07-02-2002 04:32 AM
Hi
You can clear the xlate table with the command clear xlate or you can change the timeout of the xlate (by default it is set to 3 hours) with the command timeout xlate 0:05:00 (5 min per example)
Mohammed
Regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide