Solved

Cisco Pix 501 Multiple outside ip address

Posted on 2004-09-27
3
858 Views
Last Modified: 2012-06-21
I have a Pix 501 setup and running with 1 outside IP address.  I have a couple servers behind it so I have some static route lines that route certain ports to one of the 2 servers.  I have 4 additional ip addresses available to me and I would like to use one of them.  For the purposes of this question, let's say I want to set a second web server behind the pix.  port 80 one the first IP address is already being directed to one of my existing servers.  I want to have the PIX accept requests from the 2nd ip address on port 80 and send them to the new web server (on port 80).  I know how to setup the static route and access-list.  However, where do I define that 2nd ip address?  or 3rd or 4th ip address for that matter.
0
Comment
Question by:ErnieExpert
3 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 50 total points
ID: 12163717
Example config:

ip address outside 23.34.56.7 255.255.255.248

global (outside) 1 interface
nat (inside) 1 0 0
static (inside,outside) tcp interface 80 192.168.1.100 80

To add, simply add more statics:
static (inside, outside) <public iP #2> 192.168.1.102 netmask 255.255.255.255
static (inside, outside) <public iP #3> 192.168.1.103 netmask 255.255.255.255
static (inside, outside) <public iP #4> 192.168.1.104 netmask 255.255.255.255

Now you simply add to the inbound acl list:

access-list inbound permit tcp any host <public ip #2> eq www
access-list inbound permit tcp any host <public ip #3> eq ftp
access-list inbound permit tcp any host <public ip #4> eq pop3


0
 
LVL 2

Author Comment

by:ErnieExpert
ID: 12239808
Well I guess I already new what to do then, but thanks for confirming.  I was confused because I thought that I would have to define the other ip addresses beyond just putting them in the access list and static routes, but apparently not.  I put the lines in as you suggested and it is working great.
0
 

Expert Comment

by:Sammie22
ID: 12330582
I am in a similar situation. I have six global ip's, and four servers in a data center.  Ideally, I would like the four server's global IP's to remain on the servers, and have the PIX 501 do packet filtering only. However, that doesn't seem possible (from what I have found). I guess you have to assign the inside to a private network, and give the wan interface and outside (global) ip?
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Setting up ipSec VPN between ZyXEL routers 3 36
Cisco ACS mixed versions 8 71
NSD FAIL 2 94
HSRP needed? 4 47
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now