Re: [fw-wiz] Static nat to a distant network?



-----Original Message-----
Subject: [fw-wiz] Static nat to a distant network?

Is it possible to do a static nat from my outside interface to a host
which is one hop away from my dmz
interface by just putting it in normally:

static (dmz,outside) 10.1.1.200 10.1.3.200

where:
outside = 10.1.1.199
dmz = 10.1.2.199
distant network 10.1.3.0/24

To be clear, the issue is that you want to NAT a server that is local to
your PIX's dmz interface to its outside interface? And there's a router
between the PIX's dmz interface and the server? If that's the case, then
yes, this will work just fine.

PaulM


_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Trihomed DMZ just doesnt work
    ... To be succsessful with tri-homed ISA configuration you should follow the ... You should assign your DMZ interface the IP address from the block of IPs ... And what we've got here with your configuration... ...
    (microsoft.public.isa)
  • Re: Help with creating DMZ on PIX 515E
    ... internal webserver that's connected to DMZ Interface 192.168.0.1. ... DMZ interface if you intend to initiate traffic from the DMZ to the ...
    (comp.dcom.sys.cisco)
  • Re: PIX DMZ Config help
    ... This way your inside subnet is translated for itself on the DMZ. ... PIX is translate the inside address of 192.168.2.0 for itself on the DMZ. ... I have a server connected to the DMZ interface, ...
    (comp.security.firewalls)
  • Re: [fw-wiz] PIX access-list help
    ... inside & DMZ interfaces. ... I'm a little befuddled with PIX access lists and need some help and ... dmz interface and this is where the problems start. ... inside mail server I no longer have communication to the internet from ...
    (Firewall-Wizards)
  • PIX 515 Inbound/Outbound access list confusion
    ... These are NATed to the INSIDE and the DMZ ... OUTSIDE to INSIDE allow SMTP and HTTPS ... I decided to only have 2 access lists. ... This access list was applied to the DMZ interface ...
    (comp.dcom.sys.cisco)