PIX515 Static IP

Posted on 2007-10-02
Last Modified: 2013-11-16
we have a whole block of IP's from our ISP, x.x.x.0-x.x.x.x.255. In our PIX515 i am trying to configure one server to have its own static IP. all users grab an IP from a pool x.x.x.10-x.x.x.99. a few other servers are already configured to have their own static IP's, x.x.x.200 - x.x.x.208 and that is working fine, however when i add the new one, it keeps using one of the IP's from the pool as if im not even configuring it the other way. Any idea why its not using the correct IP??

internal ip of machine,
WAN IP to use x.x.x.209
config of pix

global (outside) 1 x.x.x.10-x.x.x.99
global (outside) 1 x.x.x.100
nat (inside) 1 0 0
static (inside,outside) x.x.x.209 SER10 netmask 0 0
static (inside,outside) x.x.x.200 SER1 netmask 0 0
static (inside,outside) x.x.x.201 SER2 netmask 0 0
static (inside,outside) x.x.x.202 SER3 netmask 0 0
static (inside,outside) x.x.x.203 SER4 netmask 0 0
static (inside,outside) x.x.x.204 SER5 netmask 0 0
static (inside,outside) x.x.x.205 SER6 netmask 0 0
static (inside,outside) x.x.x.206 SER7 netmask 0 0
static (inside,outside) x.x.x.208 SER8 netmask 0 0
static (inside,outside) x.x.x.207 SER9 netmask 0 0
access-group acl_outside in interface outside
access-group outbound in interface inside
route outside x.x.x.1 1

Question by:akalbfell
    LVL 36

    Accepted Solution

    If SER10 is configured as then it should work fine. You might want to issue the 'clear xlate' command to clear and reset the translation table incase there is an existing entry confusing it.
    LVL 8

    Author Comment

    clear xlate will not cause any connection drops or anything?
    LVL 36

    Expert Comment

    It will cause any current connections to drop.
    LVL 8

    Author Comment

    yeh i thought so, ok i will do this tonight when everyone is gone and follow up. Im sure this is the problem.
    LVL 79

    Expert Comment

    What version PIX OS? Some versions older than 6.3(4) have a bug that new static xlates won't "take" until or unless the pix is rebooted.

    Featured Post

    Highfive Gives IT Their Time Back

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    Join & Write a Comment

    Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
    From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…
    Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    24 Experts available now in Live!

    Get 1:1 Help Now