nat...static ???? PIX 501 515e
Posted on 2006-04-05
First off sorry for so little points but i am ut of them have to wait till next pay day.
OK i have the following problem.
I have a pix501 at home which is connected to annother pix 515e over a tunnel preshared key. All works fine and i can conect to the inside lan of the 515e no problem.
inside 501 to inside 515 works :-)
But i would like to be able to do the following
inside 501 to 515 bnit
when i try to connect to "bnit" from inside of 501 it wont happen. I see on the syslogs that it tries to go out on the "outside" interface of the 501. I imagine it should be routing through the inside face of the 501. so either static is missing, or a nonat.
this is part of my 501 conf,
name 192.168.10.0 lan-munich
name 192.168.1.0 lan-hugh
name 10.50.51.0 bnit
access-list nonat permit ip lan-hugh 255.255.255.0 lan-munich 255.255.255.0
nat (inside) 0 access-list nonat
nat (inside) 1 0.0.0.0 0.0.0.0 0
which is natting my lan to the to the inside of the 515, i have tried the following, with no luck still tries to go over outside interface of 501. I didnt post all conf here as am not sure if need it all, i am pretty sure it is a nat problem, but i am no expert so please tell me if i am wrong, i would imagine i will need a static when the nat problem is solved ? at the moment i have no statics in my conf.
access-list nonat permit ip lan-hugh 255.255.255.0 bnit 255.255.255.0
On the 515e there are 5 interfaces
intf1 "outside" 82.135.xxx.xxx
intf2 "inside" 192.168.10.0
intf3 "a-lan" 192.168.9.0
intf4 "b-lan" 192.168.9.0
intf5 "bnit" 10.10.51.0
On the 501 there are 2 interfaces
intf1 "outside" 217.8.xxx.xxx
intf2 "inside" 192.168.1.0
Any help would be greatly appreciated.