Solved

PIX Static Translations

Posted on 2007-03-28
10
494 Views
Last Modified: 2010-04-09
Hello,

I've installed a PIX 515e. We have an Exim mail relay that sits infront of the PIX. The mail relay was connecting to our Exchange 5.5 servers before the PIX installation through a router only but now they are sitting behind the PIX. How can I get this traffic to pass through the PIX and reach the mail servers?  I don't know how to do it using a static xlate because there is one IP for the mail relay but five mail servers behind the PIX each with its own IP.
0
Comment
Question by:Ciderspine
  • 6
  • 4
10 Comments
 
LVL 28

Expert Comment

by:batry_boy
ID: 18811706
Do you have 5 public IP addresses for static translations for your mail servers?  If you don't, then you can use one IP address along with port redirection to your inside mail servers.  Post back with the info and I can explain how to do it one way or the other.
0
 

Author Comment

by:Ciderspine
ID: 18812051
Yes, I have 5 public addresses. The mail servers are already assigned public addresses if that matters.

The relay has an alias list which tells it which mail server to smart-host the mail to. So the relay has a list of 5 public addresses which correspond to the mail servers behind the PIX. Can you do static translations like NAT 0 so the address remains the same on the other side of the PIX? Hope this info helps.

Thanks,
Ben
0
 

Author Comment

by:Ciderspine
ID: 18812571
After some research, I think I've found the answer. You can static NAT an IP to itself, like so:

static (inside,outside) tcp 192.168.1.100 smtp 192.168.1.100 smtp 255.255.255.255
                                         ^ mail server behind PIX

Do you think this will work if I add a translation for each mail server?

Ben
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 28

Expert Comment

by:batry_boy
ID: 18812947
No, I would continue to use the 5 public addresses you are using now for the mail servers.  You would specify these addresses in the static command you mentioned above.  You can either implement the static using one-to-one IP address mapping that would allow you to forward any port (not just smtp) to the inbound mail server if you wanted to...or you can use the form you used above which is called port redirection where you are redirecting only specific ports (in your example, the smtp port) to the inbound server.   The syntax between the two forms is very similar.  Here is the one-to-one IP mapping syntax of the static command using 1.1.1.1 as one of your mail server's public IP addresses:

static (inside,outside) 1.1.1.1 192.168.1.100 netmask 255.255.255.255

Here is the syntax for the port redirection static command (like you used in your last post, but with the public IP address being used):

static (inside,outside) tcp 1.1.1.1 smtp 192.168.1.100 smtp netmask 255.255.255.255

So, if you were to use one-to-one mappings like I suggested above, here is the set of commands you would need to put in your PIX to get traffic flowing (assuming the following values):

Mail server public IP address 1 : 1.1.1.1
Mail server public IP address 2 : 1.1.1.2
Mail server public IP address 3 : 1.1.1.3
Mail server public IP address 4 : 1.1.1.4
Mail server public IP address 5 : 1.1.1.5
Mail server private IP address 1 : 192.168.1.100
Mail server private IP address 1 : 192.168.1.101
Mail server private IP address 1 : 192.168.1.102
Mail server private IP address 1 : 192.168.1.103
Mail server private IP address 1 : 192.168.1.104

Mail relay public IP address : 1.1.1.10

-----BEGIN COMMANDS------
static (inside,outside) 1.1.1.1 192.168.1.100 netmask 255.255.255.255
static (inside,outside) 1.1.1.2 192.168.1.101 netmask 255.255.255.255
static (inside,outside) 1.1.1.3 192.168.1.102 netmask 255.255.255.255
static (inside,outside) 1.1.1.4 192.168.1.103 netmask 255.255.255.255
static (inside,outside) 1.1.1.5 192.168.1.104 netmask 255.255.255.255
access-list acl_outside_in permit tcp host 1.1.1.10 host 1.1.1.1 eq smtp
access-list acl_outside_in permit tcp host 1.1.1.10 host 1.1.1.2 eq smtp
access-list acl_outside_in permit tcp host 1.1.1.10 host 1.1.1.3 eq smtp
access-list acl_outside_in permit tcp host 1.1.1.10 host 1.1.1.4 eq smtp
access-list acl_outside_in permit tcp host 1.1.1.10 host 1.1.1.5 eq smtp
access-group acl_outside_in in interface outside
-----END COMMANDS------

Let me know if I need to clarify any of this.
0
 

Author Comment

by:Ciderspine
ID: 18814208
I was hoping I could do it without changing the mail servers' IPs. For example, the alias list in Exim points to the mail servers IP which is a public IP. So, in order for the above to work I would have to change or assign a secondary IP to each mail server?

Ben
0
 
LVL 28

Expert Comment

by:batry_boy
ID: 18815423
The problem is that you want to move the mail servers behind the PIX which is a Layer 3 device.  This means that you have to put them on a different subnet if you want them to sit behind the PIX.  This means that you will not be able to keep the same IP addresses on the mail server since you're moving them to a different subnet.

If the mail server can have a secondary address, then this may be the way to go if you don't want to change the mail server's main IP addresses.
0
 

Author Comment

by:Ciderspine
ID: 18820011
The mail servers are already behind the PIX and they are on a different subnet. I tried  just a no NAT static translation and it's working so the relay is reaching the mail servers. Sorry about the confusion - I didn't make the question very clear at the start.

Now, strangely, I'm having a problem with creating static translations from a public IP to a private IP. Server behind the PIX has a private IP. I've added a static translation like so:

static (inside,outside) tcp 1.1.1.1. 3389 172.16.72.1 3389

The 1.1.1.1 represents a public IP from the network assigned to the PIX outside interface.

Am I right in assuming that the PIX will translate any traffic destined for port 3389 on 1.1.1.1 (access lists permitting) to 3389 on 172.16.72.1?

I just can't get it to work - it's as if it's not reaching the outside of the PIX as I can't see anything in the PIX logs.

Thanks,

Ben
0
 
LVL 28

Accepted Solution

by:
batry_boy earned 500 total points
ID: 18821034
Yes, you're understanding is correct about the use of the static command.  If you had the following 3 statements, you should be able to access an RDP session on host 172.16.72.1 by pointing your external client to 1.1.1.1:

static (inside,outside) tcp 1.1.1.1 3389 172.16.72.1 3389 netmask 255.255.255.255
access-list acl_outside_in permit tcp any host 1.1.1.1 eq 3389
access-group acl_outside_in in interface outside

Why don't you post your current PIX config and we can take a look?  It will probably clear some things up...
0
 

Author Comment

by:Ciderspine
ID: 18822048
Thanks,

Will post config later.

Ben
0
 

Author Comment

by:Ciderspine
ID: 18824990
Well, it's resolved now. I think it was a number of things but an access-list on a downstream router was the main problem. Thanks for your assistance.

Ben
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question