cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
540
Views
0
Helpful
5
Replies

static nat question

anthonytong
Level 1
Level 1

Dear all,

I would like to ask if it is possible to have the virtual ip address assigned in the higher security level zone for static nat in PIX 7.0.

i.e.

real ip in dmz: 192.168.1.1

virtual ip in inside: 172.16.1.1

dmz security level: 50

inside security level: 100

static (dmz,inside) 172.16.1.1 192.168.1.1 netmask 255.255.255.255

I encountered situation where network behind inside segment cannot reach the dmz segment and a virtual ip is needed to be assigned in the inside segment for server in dmz segment. Such nat seems not work in PIX 6.3. Thanks in advance!

Anthony

1 Accepted Solution

Accepted Solutions

jackko
Level 7
Level 7

providing you prefer not to nat between inside and dmz, do "no nat-control". with this command disabled, pix v7 will forward traffic without nat/global/static configured.

View solution in original post

5 Replies 5

haithamnofal
Level 3
Level 3

Hello Anthony,

You mentioned that you were not able to reach the DMZ from the internal network; did you apply the proper NAT configuration before trying that (i.e. NAT and Global commands)?

Anyhow, mapping the DMZ address to an inside address in the way you mentioned should work. Try "debug icmp trace" and run an ICMP test after applying this static to verify how address translation works then let us know how things move with you.

Best Regards,

Haitham

jackko
Level 7
Level 7

providing you prefer not to nat between inside and dmz, do "no nat-control". with this command disabled, pix v7 will forward traffic without nat/global/static configured.

Hi,

But wouldn't it be dangerous to disable NATting like this, as NATting is still required between inside and outside? To which extent will the effect of this command be in terms of address translation on the other interfaces?

Regrds,

Haitham

by disabling the "nat-control", it doesn't mean that you can't configure nat/global/static. all it means to the pix is that pix will permit traffic even nat/global/static is not in place.

Thanks, it works after nat-control is disabled.

Anthony