cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
830
Views
0
Helpful
2
Replies

PIX 501 setup assistance, please.

5tsparks
Level 1
Level 1

I am setting up a 501 for (small office, I'm a volunteer) security and remote admin. access behind an "Efficient Networks" Speed stream 5861 static DSL router.

How must I config the outside port address of the PIX to enable access by me from the internet?

Must it be in the same network as the outside DSL interface? DSL router will not allow same net on both sides. Different mask?

Thanks

2 Replies 2

yusuff
Cisco Employee
Cisco Employee

No, you cannot have the same subnet as your outside DSL interface. You have 2 options, either have another small PUBLIC IP address subnet for outside PIX interface or choose any Private IP address range (eg 10.1.1.0/24) and then you can NAT on the DSL router everything to the outside address of the DSL interface.

eg

PIX-----DSL-----internet

10.1.1.0/24 subnet between PIX and DSL

200.200.200.0/30 between DSL and internet

you can NAT on DSL such that everything coming from behind the DSL router is going to be NATed to DSL outside interface.

HTH

R/Yusuf

Got it. Thanks.

Review Cisco Networking for a $25 gift card