04-25-2005 08:57 AM - edited 02-21-2020 12:06 AM
I have a very large current configuration with a /24 to the outside using static to the dmz and inside. I need to add another /24 to the outside. Is there a way to nat this space in from the current outside or will I need to add the space to another interface
04-25-2005 11:16 AM
you should be able to use the other IP address space in your NAT as long as you have correct routing in place
04-25-2005 12:40 PM
I have not tried adding the nat statements yet but from reading I do not see where I can add another IP address to the current interface. Without being able to do that I do not see how I can nat into the new address space.
04-25-2005 02:43 PM
the ip address will not go on the interface. you cant assign secondary ip address to pix interface.
all you need is use static or NAT statments with the new set of IPs
04-25-2005 10:09 PM
ya ..nadeem is right.. you need not have a second interface here.. your nat statements can have any ip address and need not be a part of the present outside network.. so, just have the new pool , make statics/global with reference to the new ip addresses. make sure this new ip pool is routed through the ISP...
Raj
04-26-2005 06:41 PM
Thanks everything worked fine. I am most familiar with another firewall and it is not possible to have 2 outside network spaces.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide