cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
407
Views
0
Helpful
4
Replies

Weird issue with static translation

johnvojtech
Level 1
Level 1

I have a server that connects through the PIX 515 to the internet. It uses the global NAT or PAT pools and works just fine. I need to change it to a static IP address to connect to a customer. So I added a static translation in the PIX, did a clear xlate and clear arp commands and then the server cannot connect anything on the far end of the PIX. all internal and other legs of the firewall are fine. If I remove the static command, clear xlate, the server connects fine. I even cleared the arp on the internet routers.

Any ideas?

4 Replies 4

jaysoo
Level 1
Level 1

What's your static command? If you are referencing specific ports it won't work.

static (inside,outside) outside_IP_address internal_IP_address netmask 255.255.255.255

I allow all outbound connections.

Looks ok to me although you might want to add "0 0" at the end of the line. If your PIX isn't too busy you can try doing a logging console/buffer/monitor 4, depending where you want the output to go, and see what the errors are.

jgervia_2
Level 1
Level 1

John,

What's your complete nat configuration?

The static command you entered looks fine - I would check to make sure the IP you are using isn't part of the pool IP addresses.

--Jason

Please rate if this message helped.