06-23-2004 06:41 AM - edited 02-20-2020 11:28 PM
Hi!
Is it possibly to portmap from inside-interface to dmz-interface? (We have a web-server at the dmz-interface. The webserver "responds" at the port 446 and the clients "answers" with port 443) It works fine with portmap from outside-interface to dmz-interface.
Regards
Joakim
The configuration is attached
06-29-2004 05:40 AM
As far as I know, port redirection can be done while accessing a server on a higher security interface from a lower security interface. I am not sure if this can be done the other way.
See here for more information:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/mngacl.htm#1090663
Hope that was helpful.
07-04-2004 11:56 PM
OK, then I could set the security level lower on the inside-interface than the dmz-interface and solve this.
What about Policy-NAT (new in ver. 6.3), can I use Policy-NAT to solve this?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide