steps to creating a 1:1 address translation

Posted on 2004-11-16
Last Modified: 2010-04-10
So what are the steps to create a one-to-one address translation on a Pix and/or Microsoft VPN server
Question by:keismi2002
    LVL 36

    Accepted Solution

    Hi keismi2002,
    On the PIX you add a 'static' command in this form :-
    static (inside,outside) INTERNAL_IP_ADDRESS EXTERNAL_IP_ADDRESS netmask 0 0
    You then need to make sure the access-list applied to the outside interface permits the ports you want inbound to the NAT'd IP address.
    LVL 7

    Expert Comment

    assuming you want to setup VPN for MS VPN clients on Cisco PIX, quoted form

    How to setup VPN for MS VPN clients on Cisco PIX

    To setup VPN for MS VPN clients on Cisco PIX, you need to add the following lines.
    access-list 101 permit ip
    ip local pool bigpool
    nat (inside) 0 access-list 101
    vpdn group 1 accept dialin pptp
    vpdn group 1 ppp authentication pap
    vpdn group 1 ppp authentication chap
    vpdn group 1 ppp authentication mschap
    vpdn group 1 ppp encryption mppe 128
    vpdn group 1 client configuration address local bigpool
    vpdn group 1 client configuration dns yourdns
    vpdn group 1 client configuration wins yourwins
    vpdn group 1 pptp echo 60
    vpdn group 1 client authentication local
    vpdn username username password *********
    vpdn enable outside


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    #Citrix #Citrix Netscaler #HTTP Compression #Load Balance
    Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    13 Experts available now in Live!

    Get 1:1 Help Now