[fw-wiz] Multiple Outside IPs on Cisco PIX 6.3.3



Rather new to the advanced pix configs - I've been doing basic pix config/maint for the past 3 years.

I've got 13 public IPs that are coming in thru a cable modem to my PIX. The fist IP is routing correctly, but I can't seem to figure out how to get the PIX to accept any of the other IPs that I've bought.

Now, I'm used to the linux (redhat background) method if adding an alias to an interface, eg:
ifconfig eth0:0 1.2.3.4
ifconfig eth0:1 5.6.7.8
.. and so on and so forth.

Basically, is an equivalent operation possible with the PIX? (Running PIX ver 6.3(3))

(Of course, I'd like to be able to do static translation based on incoming IP, but I think I've got that line covered: "static (inside,outside) tcp 1.2.3.4 smtp 10.0.1.51 smtp netmask 255.255.255.255 0 0").

How do I add multiple "aliases" (for lack a better term) to the outside interface?

Thanks in advance for your patience and advice.

Regards,
Josiah Bryan

--
Josiah Bryan
IT Manager
Productive Concepts, Inc.
jbryan@xxxxxxxxxxxxxxxxxxxxxx
(765) 964-6009, ext. 224

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • PIX 501 - reaching xlate limit?
    ... Very new to the PIX so please bear with me if I'm not quite up on the ... Basically we have a bunch of public IPs and a PIX501 in the following ... DMZ Machine 1 ... however when I do a "show Xlate" I get a gradually higher number ...
    (comp.security.firewalls)
  • PIX - help with initial rules/terminology
    ... ISA External NIC (Primary Public IP + several additional public IPs) ... Soon to be PIX ... IP of the ISA and the two DMZ machines out on protocols X, Y and Z, and to ...
    (comp.security.firewalls)
  • Re: Cisco PIX-501 questions
    ... IS it possible that your Internet router is also translating the 'real' ... addresses to the ones configured on the PIX? ... > Those are the public IPs. ...
    (comp.security.firewalls)
  • Mapping IP address
    ... access-list outside-to-Inside permit tcp host 69.y.y.y host 64.x.x.x eq www ... I am running out of public IPs and I guess I have to use the PIX ... Outside IP and forward the port to internal machine, but not sure how to do ...
    (comp.dcom.sys.cisco)
  • Re: resource access behind PIX
    ... PIX ALCs to web servers on the same private range by accessing the public IPs on ... if you want an inside packet to access an inside ...
    (comp.dcom.sys.cisco)