Static Translation

Static Translation

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Static Translation Darren Green 09-16-2006
Posted by Darren Green on September 16, 2006, 2:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have an urgent PIX Change to do.

I have been asked to add a static translation to a PIX. I have a public
range on the outside of the PIX which has been further subnetted to give me
public addresses on the inside as well.

The public addresses on the outside have all been used with various static
(inside,outside) translations for LAN hosts which are reachable via a next
hop router on the inside Interface of the PIX.

The inside public address of the PIX also has a number of static
translations, these have the affect of natting the inside public addresses
to themsleves, so that it is unchanged on the outside of the Firewall.

I need to translate a new LAN host behind my inside router. As my Public
addresses on the outside of the PIX are all used, can I use one of the
Public addresses on the inside interface ?

I don't believe I can but any urgent clarification would be really
appreciated.

My network

Public Interface (Public Range - no more addresses left)
|
|
PIX
|
|
Inside Interface (Public Range Subnetted from Outside Range Above - 2/3
addresses left)
|
|
Inside Router
|
|
LAN Host I need to translate



Posted by Walter Roberson on September 16, 2006, 6:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>I have an urgent PIX Change to do.

>The inside public address of the PIX also has a number of static
>translations, these have the affect of natting the inside public addresses
>to themsleves, so that it is unchanged on the outside of the Firewall.

>I need to translate a new LAN host behind my inside router. As my Public
>addresses on the outside of the PIX are all used, can I use one of the
>Public addresses on the inside interface ?

>Public Interface (Public Range - no more addresses left)
>|
>PIX
>|
>Inside Interface (Public Range Subnetted from Outside Range Above - 2/3
>addresses left)
>|
>Inside Router
>|
>LAN Host I need to translate

Yes, if you have an available address in the public range you
use on the inside, then you have no problem. If the IP address of the
new host is in the public range, then just follow exactly the same
way as for the existing public range. If the IP address of the new
host is in a different range, then just

static (inside,outside) PUBLICIP INSIDEIP netmask 255.255.255.255

and then in your access-list for the outside interface, refer to
the PUBLICIP. In this situation, you -might- need to

route inside INSIDEIP 255.255.255.255 INSIDEROUTERIP

if you do not already have a route that moves that interior address
range towards the router.

Posted by Darren Green on September 17, 2006, 2:24 am
If you were  Registered and logged in, you could reply and use other advanced thread options

>>I have an urgent PIX Change to do.
>
>>The inside public address of the PIX also has a number of static
>>translations, these have the affect of natting the inside public addresses
>>to themsleves, so that it is unchanged on the outside of the Firewall.
>
>>I need to translate a new LAN host behind my inside router. As my Public
>>addresses on the outside of the PIX are all used, can I use one of the
>>Public addresses on the inside interface ?
>
>>Public Interface (Public Range - no more addresses left)
>>|
>>PIX
>>|
>>Inside Interface (Public Range Subnetted from Outside Range Above - 2/3
>>addresses left)
>>|
>>Inside Router
>>|
>>LAN Host I need to translate
>
> Yes, if you have an available address in the public range you
> use on the inside, then you have no problem. If the IP address of the
> new host is in the public range, then just follow exactly the same
> way as for the existing public range. If the IP address of the new
> host is in a different range, then just
>
> static (inside,outside) PUBLICIP INSIDEIP netmask 255.255.255.255
>
> and then in your access-list for the outside interface, refer to
> the PUBLICIP. In this situation, you -might- need to
>
> route inside INSIDEIP 255.255.255.255 INSIDEROUTERIP
>
> if you do not already have a route that moves that interior address
> range towards the router.

Thank you Walter.

Regards

Darren



Similar ThreadsPosted
PIX - no translation found - static has been configured ??? February 14, 2005, 2:26 pm
Pix Static Entry for Translation LIst March 13, 2006, 12:31 pm
Of Translation and ACL August 13, 2004, 10:37 am
VPN with NAT translation June 24, 2005, 6:33 am
Nat Translation June 2, 2006, 1:56 pm
IP translation - It's possible? May 8, 2007, 4:53 pm
PIX translation November 21, 2007, 2:06 am
Dynamic Outside Translation October 17, 2005, 8:29 pm
Using Cisco PIX without translation? November 8, 2005, 10:35 pm
T1/ethernet translation August 9, 2006, 10:02 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map