cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
406
Views
0
Helpful
5
Replies

pix with 2 different subnets on outside

mjhagen
Level 1
Level 1

I have a very large current configuration with a /24 to the outside using static to the dmz and inside. I need to add another /24 to the outside. Is there a way to nat this space in from the current outside or will I need to add the space to another interface

5 Replies 5

nkhawaja
Cisco Employee
Cisco Employee

you should be able to use the other IP address space in your NAT as long as you have correct routing in place

I have not tried adding the nat statements yet but from reading I do not see where I can add another IP address to the current interface. Without being able to do that I do not see how I can nat into the new address space.

the ip address will not go on the interface. you cant assign secondary ip address to pix interface.

all you need is use static or NAT statments with the new set of IPs

ya ..nadeem is right.. you need not have a second interface here.. your nat statements can have any ip address and need not be a part of the present outside network.. so, just have the new pool , make statics/global with reference to the new ip addresses. make sure this new ip pool is routed through the ISP...

Raj

Thanks everything worked fine. I am most familiar with another firewall and it is not possible to have 2 outside network spaces.

Review Cisco Networking for a $25 gift card