Solved

New PIX

Posted on 2004-04-09
3
344 Views
Last Modified: 2013-11-16
Hello,
I just got a new PIX and am trying to get it configured for my environmet, but I need some help.
With my old firewall, I was able to have only one IP address assigned to the external interface and through "redirected services" send email to my mail gateway on the internal network, web traffic to the web server in the DMZ. Is there any way to accomplish this on the PIX, or do I need to have one routable IP address for each server and have static translations for each machine?
0
Comment
Question by:MrWhitefolks
  • 2
3 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 50 total points
ID: 10793741
You can do it with just one IP:
Example:
ip address outside 1.2.3.4 255.255.255.252

! Create an access-list permitting inbound SMTP and WWW
access-list inbound_access permit tcp any host 1.2.3.4 eq 25
access-list inbound_access permit tcp any host 1.2.3.4 eq www
# alternative (might work, I've never tried it)
access-list inbound_access permit tcp any interface outside eq 25
access-list inbound_access permit tcp any interface outside eq www
!
! Create a static Port redirect from outside interface to inside host 192.168.122.22 for SMTP
! to inside host 192.168.122.33 for WWW
static (inside,outside) tcp interface 25 192.168.122.22 25 netmask 255.255.255.255
static (inside,outside) tcp interface www 192.168.122.33 www netmask 255.255.255.255
!

done.
0
 

Author Comment

by:MrWhitefolks
ID: 10793833
As a follow up to this question, what if I have a web server and an outlook web access server both running on ports 80/443. Is there any way to still only have 1 IP address, or is another one required?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 10793925
Sorry, only one translation per port...

0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
anyconnect password change 2 29
VMware vSwitch design best practice for ESXi hosts with 8x NIC ports 9 103
cisco 2911 8 34
ASA to pfsense IPSec site to site tunnel 17 42
Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
This is a video that shows how the OnPage alerts system integrates into ConnectWise, how a trigger is set, how a page is sent via the trigger, and how the SENT, DELIVERED, READ & REPLIED receipts get entered into the internal tab of the ConnectWise …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now