cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
292
Views
0
Helpful
2
Replies

PIX Help... Private network on OUTSIDE interface???

JeffG1
Level 3
Level 3

I am trying to configure a 506e with a private ip network on the outside interface... My corporate network will be on the inside interface, the users on the outside/private network will access the Internet through the corporate inside interface...

I can get this to almost work with a static map and by adding a route on the corporate network back to the private network... This will allow the outside/private network to access systems on the corporate network but not the Internet.....

Nat would be best, but my company will not allow me to turn the pix around... any suggestions?

2 Replies 2

mostiguy
Level 6
Level 6

Where are you doing nat? You need to do it somewhere?

Your config is perfectly bizarre. If you are worried about the alleged outside/private users, put them on the inside interface, and write an acl that blocks everything, and apply it to the inside interface.

There is really nothing you cannot do for blocking that you cannot do from the outside in that you can do from the inside out

I agree my company insists on puting the private network on the outside interface... They claim they can manage the pix better....

Review Cisco Networking for a $25 gift card