Link to home
Start Free TrialLog in
Avatar of maredzki
maredzki

asked on

PIX 501 service group forwarded to internal host

Hi all experts,
Is there a way to forward a service group to an internal host on the pix 501?  Basically what I need to do is open about 2000 ports to a specific host and am trying to find out if i can avoid creating 2000 translation rules...

Let me know if that is doable and how.

Thanks much!
Avatar of ruddg
ruddg

Create a single translation rule that maps one public IP to the internal host.  Create an access list that allows the port range using  the aforementioned service group.  You cannot use service groups to define NAT -- only access lists.  If you do not have an available public IP, buy a block from your provider.
Avatar of maredzki

ASKER

So are you telling me that using a single public IP I cannot do multiple service groups and/or single ports forwards to different internal hosts?  I am able to forward multiple single ports to different hosts, but cannot figure out how to do groups.

Is that my final answer from ruddg?  
ASKER CERTIFIED SOLUTION
Avatar of ruddg
ruddg

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks for your help ruddg, inspite of the answer I was looking for :-)