07-13-2002 10:58 PM - edited 02-20-2020 10:09 PM
I am setting up a 501 for (small office, I'm a volunteer) security and remote admin. access behind an "Efficient Networks" Speed stream 5861 static DSL router.
How must I config the outside port address of the PIX to enable access by me from the internet?
Must it be in the same network as the outside DSL interface? DSL router will not allow same net on both sides. Different mask?
Thanks
07-14-2002 02:30 AM
No, you cannot have the same subnet as your outside DSL interface. You have 2 options, either have another small PUBLIC IP address subnet for outside PIX interface or choose any Private IP address range (eg 10.1.1.0/24) and then you can NAT on the DSL router everything to the outside address of the DSL interface.
eg
PIX-----DSL-----internet
10.1.1.0/24 subnet between PIX and DSL
200.200.200.0/30 between DSL and internet
you can NAT on DSL such that everything coming from behind the DSL router is going to be NATed to DSL outside interface.
HTH
R/Yusuf
07-16-2002 09:55 AM
Got it. Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide