Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Public IP forward

Posted on 2004-04-06
Medium Priority
Last Modified: 2010-04-17
Is it possible to forward my supplied public IP's from my 1720 router - through a Cisco PIX506E - to my hosts in the DMZ?  So it doesn't need to be natted into private IP's?  Currently my ISP forwards me a block of 32 IP's, which are on a different subnet than their gateway and the outside interface of my router.  I have the first forwarded public IP on the inside interface and the rest go to the websites, proxy server, etc.  I just want to put a PIX in between but not lose the non-natted setup.

I want this:

Gateway from ISP  ---------->  Outside  (1720)  Inside  -------->  outside  (PIX)  inside ---------->       hosts
    66.XX.XX.1                   66.XX.XX.2         66.XX.YY.94           ?????               ??????              66.XX.YY.65 - 93
  they forward 66.XX.YY.64-95                                             forward 66.XX.YY.64-95

If the PIX is not equipped to do this, would another router be able to and how?
Question by:Popeyediceclay
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Accepted Solution

Pascal666 earned 260 total points
ID: 10772833
If you can get away with only 14 usable IPs in your DMZ, you can use 66.XX.YY.64/28 between your router and pix and put 66.XX.YY.80/28 in your DMZ.


Expert Comment

ID: 10772841
Why you need do this?
PIX do translation (NAT) any time. You can configure pix for translating ip on same ip. ( non traslating )
You can try put on PIX ip outside 66.XX.YY.65 inside 66.XX.YY.66 and non translate other ips. maybe it will work, but why then you have pix there??
Better solution is translate this ip, if you want do access your servers from outside...
Please try explain why you need do this solution...

Author Comment

ID: 10775054
Pascal- Do you mean subnet it?  Right now my subnet is, I can bump that up to and it will still work?  And use the other block of 16 on the DMZ?

mzelinka - The reason why I can't have NAT is because it doesn't work with some things, like Netmeeting
LVL 79

Assisted Solution

lrmoore earned 240 total points
ID: 10776112
You can do it with a PIX, but as Pascal points out, you have to subnet what you have so that you have different subnets inside and outside the PIX.

Netmeeting certainly does work with NAT on a PIX.

Supported Multimedia Applications
PIX Firewall supports the following multimedia and video conferencing applications:

CUseeMe Networks CU-SeeMe
CUseeMe Networks CU-SeeMe Pro
CUseeMe Networks MeetingPoint
Intel Internet Video Phone
Microsoft NetMeeting
Microsoft NetShow
RealNetworks RealAudio and RealVideo
VDOnet VDOLive
VocalTec Internet Phone
VXtreme WebTheater
Xing StreamWorks


From Microsoft:
NetMeeting and other H.323 compliant audio/video programs are not designed to work with network address translation (NAT). NAT translates all IP addresses on a local area network (LAN) to a single routable IP address.

There are some T.120 and H.323 compliant NAT implementations that work with NetMeeting. To determine if your NAT connection is compliant, consult the documentation for your NAT product.

That first statement is patently false. Their reference is to PAT, or Port Address Translation, which might, or might not work - not NAT.
The PIX fits the category in the second statement.


Featured Post

Tech or Treat! - Giveaway

Submit an article about your scariest tech experience—and the solution—and you’ll be automatically entered to win one of 4 fantastic tech gadgets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question