pix 501e config question

Posted on 2006-05-12
Last Modified: 2010-04-08

i'm needing some help here... I have a pix 501e, and i need to run two seperate ssl servers...i have 12 public ip addresses.

how do i configure pix to let me do this.  Can somone explain this to me so i can use the pdm instead of the cmd line?

Question by:rafordhargrove
    LVL 25

    Accepted Solution

    i know you want the pdm version, but sorry I only know the cli version (I just hate gui's)
    Anyway, at least for cli, this should do it

    ssl server 1  IPs
    public w.w.w.w
    private x.x.x.y

    ssl server 2 IPs
    public a.a.a.a
    private x.x.x.z

    access-list outside-in permit tcp any host w.w.w.w eq 443
    access-list outside-in permit tcp any host a.a.a.a eq 443
    access-group outside-in in interface outside

    static (inside,outside) w.w.w.w x.x.x.y netmask
    static (inside, outside) a.a.a.a x.x.x.z netmask

    just make sure that w.w.w.w or a.a.a.a are not the IP assigned to the outside interface

    LVL 51

    Expert Comment

    by:Keith Alabaster
    Cyclops has it.
    One or two other item I might add for you though.

    1. You may need to add
    no sysopt noproxyarp outside

    2. Afterwards do a cl xlate as you are amending the interface details.

    Once done, you can go back into the PDM and identify the changes. From here on, you can use the PDM as required.

    LVL 25

    Expert Comment

    don't forget to do keith's number 2
    whenever you play with nat, global, or static entries you should always clear the xlates or you could see some problems.
    LVL 51

    Expert Comment

    by:Keith Alabaster
    Your welcome,


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
    If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
    how to add IIS SMTP to handle application/Scanner relays into office 365.
    In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    11 Experts available now in Live!

    Get 1:1 Help Now