allow direct internet using pix

Dear All


I have a pix 520 firewall, i wan to allow two users to from my lan to access  the internet without prox, can someone tell me the command for this.




LVL 2
ibmas4002Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

martapCommented:

What do you mean: without prox??
0
ibmas4002Author Commented:
I mean without using ISA.
Thanks
0
martapCommented:

post your config and I the Ip's of the users.
0
jjoseph_xCommented:
Assuming that the inside interface of your PIX is the default gateway for your users you'd just need:

nat (inside) 1 0.0.0.0 0.0.0.0 0 0

Then remove any proxy settings from your web browser (if applicable) and you ought to be in business.  This does give everyone close to no-holds-barred internet access without any monitoring, content filtering, or service blocking though (which is the big advantage of a proxy server).

I hope that helps.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
jjoseph_xCommented:
If you ONLY want those two usage to have access to the internet and no one else, you could instead just use a nat (inside) command for the IP address of those specific users.

For instance, if you give those two users static IP addresses or give them DCHP reservations (let's say 192.168.1.11 and 192.168.1.12 both /24) you could do something like this:

nat (inside) 1 192.168.1.11 255.255.255.0 0 0
nat (inside) 2 192.168.1.12 255.255.255.0 0 0
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.