03-22-2016 08:58 AM - edited 03-12-2019 12:32 AM
Hi Everyone,
I need to config ACL for traffic flow from outside to inside in PIX515.
Need help on NAT config for this?
Regards
MAhesh
Solved! Go to Solution.
03-22-2016 09:12 AM
Hi Mahesh,
You need to more specific
Here is an example:
static (inside,outside) MAPPED IP REAL IP netmask 255.255.255.255
Regards,
Aditya
Please rate helpful posts.
03-22-2016 11:07 AM
Yes this is called a STATIC Identity NAT.
So you would access the internal IP from outside as the original IP.
Yes this would would work.
Regards,
Aditya
Please rate helpful posts and mark correct answers.
03-22-2016 09:10 AM
Here is a doc for your reference:-
http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/12496-28.html#topic12
Regards,
Dinesh Moudgil
P.S. Please rate helpful posts.
03-22-2016 09:12 AM
Hi Mahesh,
You need to more specific
Here is an example:
static (inside,outside) MAPPED IP REAL IP netmask 255.255.255.255
Regards,
Aditya
Please rate helpful posts.
03-22-2016 09:16 AM
Say if source from outside is 10.40.x.x and inside is 174.24.x.x
what config should i put then?
Regards
MAhesh
03-22-2016 09:22 AM
Hi Mahesh,
Here is the command you would use:
static (inside,outside) <mapped IP> <174.24.x.x>
Also on the outside ACL you need to allow source as any and destination would be the MAPPED IP.
Regards,
Aditya
Please rate helpful posts.
03-22-2016 09:37 AM
what IP should i put under mapped ip?
03-22-2016 09:41 AM
Hi Mahesh,
The IP you would use to access the inside server from outside.
So
So my
static (inside,outside) 1.1.1.1 10.1.1.1
Remember I can come from any IP from outside.
Regards,
Aditya
03-22-2016 10:19 AM
if i use this command
static (inside,outside) 174.24.x.x <174.24.x.x> netmask 255.255.255.255
this will do no nat right?
03-22-2016 11:07 AM
Yes this is called a STATIC Identity NAT.
So you would access the internal IP from outside as the original IP.
Yes this would would work.
Regards,
Aditya
Please rate helpful posts and mark correct answers.
03-22-2016 12:21 PM
Many thanks !
Regards
Mahesh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide