cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
263
Views
0
Helpful
2
Replies

Pix515e - NAT or Route?

samuk
Level 1
Level 1

Hello there

I've got about 5 servers in a datacenter and have a whole range of public IP addresses. All the servers have public IP address(es). These servers are mainly used for webservices (Mail, Web, DNS etc...)

Should I NAT the IP addresses through the PIX or route them through? At the moment I'm using NAT. A collegue has suggested the routing would be a better option since it will be less depending on resources.

Any info/advice on this would be greatly appreaciated.

Many thanks,

Sam

2 Replies 2

scoclayton
Level 7
Level 7

In my opinion, it makes no real difference. At the current time, the PIX has to create a translation for each flow through the PIX. This is the case even if you are "no-natting" the traffic through the PIX (ie routing the packets through the PIX). You will still create a static for the hosts protected by the PIX, it would just look something like this:

static (inside,outside) 1.1.1.1 1.1.1.1 netmask 255.255.255.255

This still takes the same amount of memory blocks as NAT'ing the traffic to a private address on the inside. Hope this helps.

Scott

Many thanks Scott