11-02-2006 01:34 PM - edited 03-09-2019 04:45 PM
I have a server that connects through the PIX 515 to the internet. It uses the global NAT or PAT pools and works just fine. I need to change it to a static IP address to connect to a customer. So I added a static translation in the PIX, did a clear xlate and clear arp commands and then the server cannot connect anything on the far end of the PIX. all internal and other legs of the firewall are fine. If I remove the static command, clear xlate, the server connects fine. I even cleared the arp on the internet routers.
Any ideas?
11-02-2006 01:40 PM
What's your static command? If you are referencing specific ports it won't work.
11-02-2006 01:44 PM
static (inside,outside) outside_IP_address internal_IP_address netmask 255.255.255.255
I allow all outbound connections.
11-02-2006 02:01 PM
Looks ok to me although you might want to add "0 0" at the end of the line. If your PIX isn't too busy you can try doing a logging console/buffer/monitor 4, depending where you want the output to go, and see what the errors are.
11-02-2006 05:05 PM
John,
What's your complete nat configuration?
The static command you entered looks fine - I would check to make sure the IP you are using isn't part of the pool IP addresses.
--Jason
Please rate if this message helped.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide