maredzki
asked on
PIX 501 service group forwarded to internal host
Hi all experts,
Is there a way to forward a service group to an internal host on the pix 501? Basically what I need to do is open about 2000 ports to a specific host and am trying to find out if i can avoid creating 2000 translation rules...
Let me know if that is doable and how.
Thanks much!
Is there a way to forward a service group to an internal host on the pix 501? Basically what I need to do is open about 2000 ports to a specific host and am trying to find out if i can avoid creating 2000 translation rules...
Let me know if that is doable and how.
Thanks much!
Create a single translation rule that maps one public IP to the internal host. Create an access list that allows the port range using the aforementioned service group. You cannot use service groups to define NAT -- only access lists. If you do not have an available public IP, buy a block from your provider.
ASKER
So are you telling me that using a single public IP I cannot do multiple service groups and/or single ports forwards to different internal hosts? I am able to forward multiple single ports to different hosts, but cannot figure out how to do groups.
Is that my final answer from ruddg?
Is that my final answer from ruddg?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thanks for your help ruddg, inspite of the answer I was looking for :-)