cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
312
Views
0
Helpful
2
Replies

PIX Portmap from inside-interface to dmz-interface, Is this possibly?

jmix
Level 1
Level 1

Hi!

Is it possibly to portmap from inside-interface to dmz-interface? (We have a web-server at the dmz-interface. The webserver "responds" at the port 446 and the clients "answers" with port 443) It works fine with portmap from outside-interface to dmz-interface.

Regards

Joakim

The configuration is attached

2 Replies 2

didyap
Level 6
Level 6

As far as I know, port redirection can be done while accessing a server on a higher security interface from a lower security interface. I am not sure if this can be done the other way.

See here for more information:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/mngacl.htm#1090663

Hope that was helpful.

OK, then I could set the security level lower on the inside-interface than the dmz-interface and solve this.

What about Policy-NAT (new in ver. 6.3), can I use Policy-NAT to solve this?

Review Cisco Networking for a $25 gift card