PIX 501, single public IP, multiple physical web servers

Posted on 2007-07-23
Medium Priority
Last Modified: 2012-05-05

First time I'm actually asking a question, hoping someone has the answer.....

Description of situation:
- PIX 501
- Single public IP address
- 1 physical web server hosting 2 web sites
- DNS set up to map both web sites to the same public IP
  (eg: www.abc.net and www.def.org both use the same public IP)
- PIX 501 maps public IP to the physical server for port 80
- IIS handles HTTP request using host header to map to the right web site

Now I want to add another physical server hosting 3 web sites. This physical server obviously will be given another private IP address. There is however no possibility to get another public IP to map to this new server and the web sites it runs.

Is there any way to get the PIX to handle this "problem", ie use the same public IP for all 5 web sites and have the respective IIS installations on the physical servers to map to the proper we site?

I've been pondering this for a while now, but being new to Cisco I'm not getting any further. Help would be very much appreciated.

Question by:RayCore
  • 2
LVL 31

Expert Comment

ID: 19550893
i would say only when using different ports? or?

Author Comment

ID: 19550966

I can have the 2nd web server listen in on another port alright, but can PIX 501 distinguish between different web site lookups?

What I mean by this: if someone asks for www.abc.nl, which I know is on the 2nd server using let's say port 81, how can I let the PIX map to this physical server.....? So how does PIX know, that www.abc.nl has to be mapped to the internal IP of this server listening on port 81 and not to the 1st physical server using port 80?

And if PIX can do this, what would be the answer to my problem, what would the proper syntax be?

Thanks for thinking along.


Accepted Solution

parbul earned 375 total points
ID: 19552551

No,  the pix  can´t do that,    for do that you need a  7 layer firewall  like a proxy (isa server for example)

Sorry  i am very  sure  in this  answer.

Author Comment

ID: 19554993
Thanks Parbul,

Checked some other sites as well and they agree with you. This is something that can be performed by something like a router or such, but not a lower-layer firewall like this.


Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Preparing an email is something we should all take special care with – especially when the email is for somebody you may not know very well. The pressures of everyday working life stacked with a hectic office environment can make this a real challen…
As managed cloud service providers, we often get asked to intervene when cloud deployments go awry. Attracted by apparent ease-of-use, flexibility and low computing costs, companies quickly adopt leading public cloud platforms such as Amazon Web Ser…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question