Solved

Cisco Pix 501 Multiple outside ip address

Posted on 2004-09-27
3
864 Views
Last Modified: 2012-06-21
I have a Pix 501 setup and running with 1 outside IP address.  I have a couple servers behind it so I have some static route lines that route certain ports to one of the 2 servers.  I have 4 additional ip addresses available to me and I would like to use one of them.  For the purposes of this question, let's say I want to set a second web server behind the pix.  port 80 one the first IP address is already being directed to one of my existing servers.  I want to have the PIX accept requests from the 2nd ip address on port 80 and send them to the new web server (on port 80).  I know how to setup the static route and access-list.  However, where do I define that 2nd ip address?  or 3rd or 4th ip address for that matter.
0
Comment
Question by:ErnieExpert
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 50 total points
ID: 12163717
Example config:

ip address outside 23.34.56.7 255.255.255.248

global (outside) 1 interface
nat (inside) 1 0 0
static (inside,outside) tcp interface 80 192.168.1.100 80

To add, simply add more statics:
static (inside, outside) <public iP #2> 192.168.1.102 netmask 255.255.255.255
static (inside, outside) <public iP #3> 192.168.1.103 netmask 255.255.255.255
static (inside, outside) <public iP #4> 192.168.1.104 netmask 255.255.255.255

Now you simply add to the inbound acl list:

access-list inbound permit tcp any host <public ip #2> eq www
access-list inbound permit tcp any host <public ip #3> eq ftp
access-list inbound permit tcp any host <public ip #4> eq pop3


0
 
LVL 2

Author Comment

by:ErnieExpert
ID: 12239808
Well I guess I already new what to do then, but thanks for confirming.  I was confused because I thought that I would have to define the other ip addresses beyond just putting them in the access list and static routes, but apparently not.  I put the lines in as you suggested and it is working great.
0
 

Expert Comment

by:Sammie22
ID: 12330582
I am in a similar situation. I have six global ip's, and four servers in a data center.  Ideally, I would like the four server's global IP's to remain on the servers, and have the PIX 501 do packet filtering only. However, that doesn't seem possible (from what I have found). I guess you have to assign the inside to a private network, and give the wan interface and outside (global) ip?
0

Featured Post

Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
It happens many times that access list (ACL) have to be applied to outgoing router interface in order to limit some traffic.This article is about how to test ACL from the router which is not very intuitive for everyone. Below scenario shows simple s…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month8 days, 11 hours left to enroll

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question