sheikham88
asked on
pix without nat
how should i configure a pix 506e firewall so that it does not perform nat and only does routing between its inside and outside network.
What exactly is the problem right now ? Since if you are using private ip addresses inside and outside interface connected to internet, it will not work.
If you can explain more, we'll be able to understand the problem.
Cheers,
Rajesh
If you can explain more, we'll be able to understand the problem.
Cheers,
Rajesh
He only said he does not want the PIX to nat. He is probably doing NAT on the router and it will work if configured that way.
ASKER
yes atif awan is write i am doing nat on the router
to further clarify why i dont want nat to happen on the pix is because i have a dmvpn network for which this router is acting as a primary hub now when i do nat on the pix the public ip address range between the router and the pix is required to be published in all the routers in my dmvpn network which i dont want.
now when i will avoid nat happening on the pix then i will have a complete private ip network on the intranet side i hope i have made my self clear
now atifawan if i give this command on the pix it will not do nat and allow all connections from the outside to the inside interface is this correct
to further clarify why i dont want nat to happen on the pix is because i have a dmvpn network for which this router is acting as a primary hub now when i do nat on the pix the public ip address range between the router and the pix is required to be published in all the routers in my dmvpn network which i dont want.
now when i will avoid nat happening on the pix then i will have a complete private ip network on the intranet side i hope i have made my self clear
now atifawan if i give this command on the pix it will not do nat and allow all connections from the outside to the inside interface is this correct
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
one last thing about my question, can i not have any kind of nat on pix to make it work or is it necessary to have some kind of nat to make the pix work as a router and also to have firewall functionality.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
nat (inside) 0 0 0
This will pass all IP Addresses on the inside interface to outside without Natting them. If you want to be more specific you can also specify which addresses you do not want to be natted.